CVE-2019-1940

A vulnerability in the Web Services Management Agent (WSMA) feature of Cisco Industrial Network Director (IND) could allow an unauthenticated, remote attacker to gain unauthorized read access to sensitive data using an invalid X.509 certificate. The vulnerability is due to insufficient X.509 certificate validation when establishing a WSMA connection. An attacker could exploit this vulnerability by supplying a crafted X.509 certificate during the WSMA connection setup phase. A successful exploit could allow the attacker to conduct man-in-the-middle attacks to decrypt confidential information on WSMA connections to the affected software. At the time of publication, this vulnerability affected Cisco IND Software releases prior to 1.7.
Configurations

Configuration 1 (hide)

cpe:2.3:a:cisco:industrial_network_director:*:*:*:*:*:*:*:*

History

21 Nov 2024, 04:37

Type Values Removed Values Added
References () http://www.securityfocus.com/bid/109296 - Third Party Advisory, VDB Entry () http://www.securityfocus.com/bid/109296 - Third Party Advisory, VDB Entry
References () https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190717-wsma-info - Vendor Advisory () https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190717-wsma-info - Vendor Advisory

Information

Published : 2019-07-17 21:15

Updated : 2024-11-21 04:37


NVD link : CVE-2019-1940

Mitre link : CVE-2019-1940

CVE.ORG link : CVE-2019-1940


JSON object : View

Products Affected

cisco

  • industrial_network_director
CWE
CWE-310

Cryptographic Issues

CWE-295

Improper Certificate Validation