CVE-2019-5492 describes a sensitive information disclosure vulnerability affecting Element Plug-in for vCenter Server versions prior to 4.2.3 and NetApp HCI Compute Node versions prior to 1.4P2. An unauthenticated attacker can exploit this flaw to obtain sensitive account information. With a CVSS score of 7.5 (High), this vulnerability has a low attack complexity and requires no user interaction, allowing remote attackers to achieve high confidentiality impact. Despite its severity, there is no known public exploit code, Metasploit modules, or Nuclei templates, and it has received no community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 1.4CPE matchmatch criteria | cpe:2.3:a:netapp:hyper_converged_infrastructure_compute_node:*:*:*:*:*:*:*:* | ||
< 4.2.3CPE matchmatch criteria | cpe:2.3:a:netapp:element_plug-in_for_vcenter_server:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.