U.S. flag   An official website of the United States government
Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Https

Secure .gov websites use HTTPS
A lock (Dot gov) or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites.

Vulnerability Change Records for CVE-2019-12491

Change History

Initial Analysis by NIST 6/21/2019 12:30:24 PM

Action Type Old Value New Value
Added CPE Configuration

								
							
							
						
OR
     *cpe:2.3:a:onapp:onapp:5.0.0:-:*:*:*:*:*:*
     *cpe:2.3:a:onapp:onapp:5.0.0:update_79:*:*:*:*:*:*
     *cpe:2.3:a:onapp:onapp:5.0.0:update_82:*:*:*:*:*:*
     *cpe:2.3:a:onapp:onapp:5.0.0:update_83:*:*:*:*:*:*
     *cpe:2.3:a:onapp:onapp:5.0.0:update_87:*:*:*:*:*:*
     *cpe:2.3:a:onapp:onapp:5.1.0:-:*:*:*:*:*:*
     *cpe:2.3:a:onapp:onapp:5.1.0:update_16:*:*:*:*:*:*
     *cpe:2.3:a:onapp:onapp:5.2.0:-:*:*:*:*:*:*
     *cpe:2.3:a:onapp:onapp:5.3.0:-:*:*:*:*:*:*
     *cpe:2.3:a:onapp:onapp:5.3.0:update_41:*:*:*:*:*:*
     *cpe:2.3:a:onapp:onapp:5.4.0:-:*:*:*:*:*:*
     *cpe:2.3:a:onapp:onapp:5.4.0:update_66:*:*:*:*:*:*
     *cpe:2.3:a:onapp:onapp:5.4.0:update_70:*:*:*:*:*:*
     *cpe:2.3:a:onapp:onapp:5.4.0:update_72:*:*:*:*:*:*
     *cpe:2.3:a:onapp:onapp:5.4.0:update_76:*:*:*:*:*:*
     *cpe:2.3:a:onapp:onapp:5.4.0:update_82:*:*:*:*:*:*
     *cpe:2.3:a:onapp:onapp:5.4.0:update_84:*:*:*:*:*:*
     *cpe:2.3:a:onapp:onapp:5.5.0:-:*:*:*:*:*:*
     *cpe:2.3:a:onapp:onapp:5.5.0:update_50:*:*:*:*:*:*
     *cpe:2.3:a:onapp:onapp:5.5.0:update_59:*:*:*:*:*:*
     *cpe:2.3:a:onapp:onapp:5.5.0:update_65:*:*:*:*:*:*
     *cpe:2.3:a:onapp:onapp:5.5.0:update_75:*:*:*:*:*:*
     *cpe:2.3:a:onapp:onapp:5.5.0:update_80:*:*:*:*:*:*
     *cpe:2.3:a:onapp:onapp:5.5.0:update_83:*:*:*:*:*:*
     *cpe:2.3:a:onapp:onapp:5.5.0:update_87:*:*:*:*:*:*
     *cpe:2.3:a:onapp:onapp:5.5.0:update_90:*:*:*:*:*:*
     *cpe:2.3:a:onapp:onapp:5.5.0:update_92:*:*:*:*:*:*
     *cpe:2.3:a:onapp:onapp:5.6.0:-:*:*:*:*:*:*
     *cpe:2.3:a:onapp:onapp:5.6.0:update_83:*:*:*:*:*:*
     *cpe:2.3:a:onapp:onapp:5.7.0:-:*:*:*:*:*:*
     *cpe:2.3:a:onapp:onapp:5.8.0:-:*:*:*:*:*:*
     *cpe:2.3:a:onapp:onapp:5.9.0:-:*:*:*:*:*:*
     *cpe:2.3:a:onapp:onapp:5.10.0:-:*:*:*:*:*:*
     *cpe:2.3:a:onapp:onapp:6.0:update_122:*:*:*:*:*:*
     *cpe:2.3:a:onapp:onapp:6.0:update_152:*:*:*:*:*:*
     *cpe:2.3:a:onapp:onapp:6.0:update_159:*:*:*:*:*:*
     *cpe:2.3:a:onapp:onapp:6.0:update_62:*:*:*:*:*:*
     *cpe:2.3:a:onapp:onapp:6.0:update_80:*:*:*:*:*:*
     *cpe:2.3:a:onapp:onapp:6.0:update_98:*:*:*:*:*:*
     *cpe:2.3:a:onapp:onapp:6.0.0:-:*:*:*:*:*:*
Added CVSS V2

								
							
							
						
(AV:N/AC:M/Au:S/C:C/I:C/A:C)
Added CVSS V3

								
							
							
						
AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H
Added CWE

								
							
							
						
CWE-77
Changed Reference Type
https://docs.onapp.com/rn/general-security-advisory No Types Assigned
https://docs.onapp.com/rn/general-security-advisory Mitigation, Patch, Release Notes, Vendor Advisory
Changed Reference Type
https://skylightcyber.com/2019/06/07/all-your-cloud-are-belong-to-us-cve-2019-12491/ No Types Assigned
https://skylightcyber.com/2019/06/07/all-your-cloud-are-belong-to-us-cve-2019-12491/ Third Party Advisory