← Back

CVE-2019-1975

nvd nist
Published: Sep 18, 2019Modified: Jun 17, 2026

JSON object

Loading...
6.1
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Exploitability: 2.8 / Impact: 2.7
Source: NVD

Description

A vulnerability in the web-based interface of Cisco HyperFlex Software could allow an unauthenticated, remote attacker to execute a cross-frame scripting (XFS) attack on an affected device. This vulnerability is due to insufficient HTML iframe protection. An attacker could exploit this vulnerability by directing a user to an attacker-controlled web page that contains a malicious HTML iframe. A successful exploit could allow the attacker to conduct clickjacking or other clientside browser attacks.

Affected (10)

5 products
Hyperflex Hx220c M5 Firmware
Hyperflex Hx240c M5 Firmware
Hyperflex Hx220c Af M5 Firmware
Hyperflex Hx240c Af M5 Firmware
Hyperflex Hx220c Edge M5 Firmware
Configuration A
2 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Cisco
Up to 3.5.2f
Version 4.0(1a)
Running on/withPlatform Versions
Cisco
Hyperflex Hx220c M5
All versions
Configuration B
2 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Cisco
Up to 3.5.2f
Version 4.0(1a)
Running on/withPlatform Versions
Cisco
Hyperflex Hx240c M5
All versions
Configuration C
2 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Cisco
Up to 3.5.2f
Version 4.0(1a)
Running on/withPlatform Versions
Cisco
Hyperflex Hx220c Af M5
All versions
Configuration D
2 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Cisco
Up to 3.5.2f
Version 4.0(1a)
Running on/withPlatform Versions
Cisco
Hyperflex Hx240c Af M5
All versions
Configuration E
2 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Cisco
Up to 3.5.2f
Version 4.0(1a)
Running on/withPlatform Versions
Cisco
Hyperflex Hx220c Edge M5
All versions

Timeline

No history available yet.