CVE-2019-1234
high · 7.5A spoofing vulnerability exists when Azure Stack fails to validate certain requests, aka 'Azure Stack Spoofing Vulnerability'.
7.5
CVSS
75.2%
EPSS (exploit prob.)
99th
EPSS percentile
2019-11-12
Published
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Weaknesses
CWE-290
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| microsoft | azure_stack | all versions |
Check a specific version with /api/v1/cve/match.
References
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-1234
- https://research.checkpoint.com/2020/remote-cloud-execution-critical-vulnerabilities-in-azure-cloud-infrastructure-part-i/
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-1234
- https://research.checkpoint.com/2020/remote-cloud-execution-critical-vulnerabilities-in-azure-cloud-infrastructure-part-i/
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2019-1234