VDB
CVE-2019-16004
CVE-2019-16004
PUBLISHED
CVSS 6.5 MEDIUM
A vulnerability in the REST API endpoint of Cisco Vision Dynamic Signage Director could allow an unauthenticated, remote attacker to bypass authentication on an affected device. The vulnerability is due to missing authentication on some of the API calls. An attacker could exploit this vulnerability by sending a request to one of the affected calls. A successful exploit could allow the attacker to interact with some parts of the API.
EPSS 1.03% · 61.3th percentile
Risk Scores
CVSS 3.0
6.5
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
EPSS Score
1.03%
61.3th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| cisco | vision_dynamic_signage_director | 0, 6.2.0, 6.2.0 |
| Cisco | Cisco Vision Dynamic Signage Director | n/a |
Timeline
- Sep 23, 2020 CVE Published
- Apr 14, 2021 EPSS Score
- Jun 23, 2021 EPSS Score
- Aug 25, 2021 EPSS Score
- Dec 28, 2021 EPSS Score
- Jan 6, 2022 EPSS Score
- Feb 4, 2022 EPSS Score
- Mar 1, 2022 EPSS Score
- Apr 1, 2022 EPSS Score
- May 3, 2022 EPSS Score
- May 24, 2022 CVE Updated
- Sep 6, 2022 EPSS Score