Vulnerability Details CVE-2019-19632
An issue was discovered in Big Switch Big Monitoring Fabric 6.2 through 6.2.4, 6.3 through 6.3.9, 7.0 through 7.0.3, and 7.1 through 7.1.3; Big Cloud Fabric 4.5 through 4.5.5, 4.7 through 4.7.7, 5.0 through 5.0.1, and 5.1 through 5.1.4; and Multi-Cloud Director through 1.1.0. An unauthenticated attacker may inject stored arbitrary JavaScript (XSS), and execute it in the content of authenticated administrators.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.014
EPSS Ranking 80.0%
CVSS Severity
CVSS v3 Score 6.1
CVSS v2 Score 4.3
Products affected by CVE-2019-19632
-
cpe:2.3:a:bigswitch:big_cloud_fabric:4.5
-
cpe:2.3:a:bigswitch:big_cloud_fabric:4.7
-
cpe:2.3:a:bigswitch:big_cloud_fabric:5.0
-
cpe:2.3:a:bigswitch:big_cloud_fabric:5.1
-
cpe:2.3:a:bigswitch:big_monitoring_fabric:6.2
-
cpe:2.3:a:bigswitch:big_monitoring_fabric:6.3
-
cpe:2.3:a:bigswitch:big_monitoring_fabric:7.0
-
cpe:2.3:a:bigswitch:big_monitoring_fabric:7.1
-
cpe:2.3:a:bigswitch:multi-cloud_director:-