8.8

CVE-2019-19631

Exploit
An issue was discovered in Big Switch Big Monitoring Fabric 6.2 through 6.2.4, 6.3 through 6.3.9, 7.0 through 7.0.3, and 7.1 through 7.1.3; Big Cloud Fabric 4.5 through 4.5.5, 4.7 through 4.7.7, 5.0 through 5.0.1, and 5.1 through 5.1.4; and Multi-Cloud Director through 1.1.0. A read-only user can access sensitive information via an API endpoint that reveals session cookies of authenticated administrators, leading to privilege escalation.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
BigswitchBig Cloud Fabric Version >= 4.5 < 4.5.5
BigswitchBig Cloud Fabric Version >= 4.7 < 4.7.7
BigswitchBig Cloud Fabric Version >= 5.0 < 5.0.1
BigswitchBig Cloud Fabric Version >= 5.1 < 5.1.4
BigswitchBig Monitoring Fabric Version >= 6.2 < 6.2.4
BigswitchBig Monitoring Fabric Version >= 6.3 < 6.3.9
BigswitchBig Monitoring Fabric Version >= 7.0 < 7.0.3
BigswitchBig Monitoring Fabric Version >= 7.1 < 7.1.4
BigswitchMulti-cloud Director Version < 1.1.0
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.95% 0.757
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 8.8 2.8 5.9
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 6.5 8 6.4
AV:N/AC:L/Au:S/C:P/I:P/A:P
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.