AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2019-19127

HIGH · CVSS 8.1 EPSS 1.25% Public Exploit

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2020-03-25 · Last synced 2026-08-04

CyberRota Analysis

This is a high severity vulnerability with a CVSS score of 8.1. Public exploit code or proof-of-concept references have been detected in its references.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

External Security References

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2019-19127
Severity
HIGH
CVSS
8.1
EPSS
1.25%

Original NVD Description

An authentication bypass vulnerability is present in the standalone SITS:Vision 9.7.0 component of Tribal SITS in its default configuration, related to unencrypted communications sent by the client each time it is launched. This occurs because the Uniface TLS Driver is not enabled by default. This vulnerability allows attackers to gain access to credentials or execute arbitrary SQL queries on the SITS backend as long as they have access to the client executable or can intercept traffic from a user who does.