4.3
CVSSv3

CVE-2019-1645

Published: 24/01/2019 Updated: 09/10/2019
CVSS v2 Base Score: 3.3 | Impact Score: 2.9 | Exploitability Score: 6.5
CVSS v3 Base Score: 4.3 | Impact Score: 1.4 | Exploitability Score: 2.8
VMScore: 294
Vector: AV:A/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

A vulnerability in the Cisco Connected Mobile Experiences (CMX) software could allow an unauthenticated, adjacent malicious user to access sensitive data on an affected device. The vulnerability is due to a lack of input and validation checking mechanisms for certain GET requests to API's on an affected device. An attacker could exploit this vulnerability by sending HTTP GET requests to an affected device. An exploit could allow the malicious user to use this information to conduct additional reconnaissance attacks.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

cisco connected mobile experiences 10.2\\(1.0\\)

Vendor Advisories

A vulnerability in the Cisco Connected Mobile Experiences (CMX) software could allow an unauthenticated, adjacent attacker to access sensitive data on an affected device The vulnerability is due to a lack of input and validation checking mechanisms for certain GET requests to API's on an affected device An attacker could exploit this vulnerabili ...