Vulnerability Description
A vulnerability in the management interface of Cisco Application Policy Infrastructure Controller (APIC) software could allow an unauthenticated, adjacent attacker to gain unauthorized access on an affected device. The vulnerability is due to a lack of proper access control mechanisms for IPv6 link-local connectivity imposed on the management interface of an affected device. An attacker on the same physical network could exploit this vulnerability by attempting to connect to the IPv6 link-local address on the affected device. A successful exploit could allow the attacker to bypass default access control restrictions on an affected device. Cisco Application Policy Infrastructure Controller (APIC) devices running versions prior to 4.2(0.21c) are affected.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Cisco | Application Policy Infrastructure Controller | < 4.2\(0.21c\) |
| Cisco | Firepower 2110 | - |
| Cisco | Firepower 2120 | - |
| Cisco | Firepower 2130 | - |
| Cisco | Firepower 2140 | - |
| Cisco | Firepower 4110 | - |
| Cisco | Firepower 4112 | - |
| Cisco | Firepower 4115 | - |
| Cisco | Firepower 4120 | - |
| Cisco | Firepower 4125 | - |
| Cisco | Firepower 4140 | - |
| Cisco | Firepower 4145 | - |
| Cisco | Firepower 4150 | - |
| Cisco | Firepower 9300 | - |
| Cisco | Mds 9100 | - |
| Cisco | Mds 9134 | - |
| Cisco | Mds 9509 | - |
| Cisco | Mds 9710 | - |
| Cisco | Nexus 3016 | - |
| Cisco | Nexus 3048 | - |
Related Weaknesses (CWE)
References
- http://www.securityfocus.com/bid/107317Third Party AdvisoryVDB Entry
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-2Vendor Advisory
- http://www.securityfocus.com/bid/107317Third Party AdvisoryVDB Entry
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-2Vendor Advisory
FAQ
What is CVE-2019-1690?
CVE-2019-1690 is a vulnerability with a CVSS score of 6.5 (MEDIUM). A vulnerability in the management interface of Cisco Application Policy Infrastructure Controller (APIC) software could allow an unauthenticated, adjacent attacker to gain unauthorized access on an af...
How severe is CVE-2019-1690?
CVE-2019-1690 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-1690?
Check the references section above for vendor advisories and patch information. Affected products include: Cisco Application Policy Infrastructure Controller, Cisco Firepower 2110, Cisco Firepower 2120, Cisco Firepower 2130, Cisco Firepower 2140.