CVE-2019-1863
8.1
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
Exploitability: 2.8 / Impact: 5.2
Source: NVD
Description
A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) Software could allow an authenticated, remote attacker to make unauthorized changes to the system configuration. The vulnerability is due to insufficient authorization enforcement. An attacker could exploit this vulnerability by sending a crafted HTTP request to the affected software. A successful exploit could allow a user with read-only privileges to change critical system configurations using administrator privileges.
Affected (7)
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Version 4.0(1c)hs3 |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| From 1.5.0.0 to 1.5\(9g\) |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| From 4.0.0.0 to 4.0\(1d\) |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| From 4.0.0.0 to 4.0\(2c\) |
| Running on/with | Platform Versions |
|---|---|
Cisco Encs 5100 | All versions |
Cisco Encs 5400 | All versions |
Cisco Ucs E1120d M3 | All versions |
Cisco Ucs E140s M2 | All versions |
Cisco Ucs E160d M2 | All versions |
Cisco Ucs E160s M3 | All versions |
Cisco Ucs E168d M2 | All versions |
Cisco Ucs E180d M3 | All versions |
Cisco Ucs C125 M5 | All versions |
Cisco Ucs C4200 | All versions |
Cisco Ucs S3260 | All versions |
References (2)
Source: psirt@cisco.com
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Timeline
No history available yet.