CVE-2019-16029 is a critical vulnerability in Cisco Smart Software Manager On-Prem's API, stemming from a lack of input validation. An unauthenticated, remote attacker can exploit this by sending a crafted HTTP request to alter or corrupt user account information. This can lead to a denial of service for legitimate users by preventing login, or potentially grant the attacker administrator access. While rated 9.1 Critical, there is no evidence of active exploitation, public exploit code, or significant community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 7-201910CPE matchmatch criteria | cpe:2.3:a:cisco:smart_software_manager_on-prem:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.