CVE-2019-1865
8.8
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 2.8 / Impact: 5.9
Source: NVD
Description
A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) Software could allow an authenticated, remote attacker to inject arbitrary commands that are executed with root privileges on an affected device. The vulnerability is due to insufficient validation of user-supplied input by the affected software. An attacker could exploit this vulnerability by invoking an interface monitoring mechanism with a crafted argument on the affected software. A successful exploit could allow the attacker to inject and execute arbitrary, system-level commands with root privileges on an affected device.
Affected (7)
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Version 4.0(1c)hs3 |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| From 1.5.0.0 to 1.5\(9g\) |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| From 4.0.0.0 to 4.0\(1d\) |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| From 4.0.0.0 to 4.0\(2c\) |
| Running on/with | Platform Versions |
|---|---|
Cisco Encs 5100 | All versions |
Cisco Encs 5400 | All versions |
Cisco Ucs E1120d M3 | All versions |
Cisco Ucs E140s M2 | All versions |
Cisco Ucs E160d M2 | All versions |
Cisco Ucs E160s M3 | All versions |
Cisco Ucs E168d M2 | All versions |
Cisco Ucs E180d M3 | All versions |
Cisco Ucs C125 M5 | All versions |
Cisco Ucs C4200 | All versions |
Cisco Ucs S3260 | All versions |
References (2)
Source: psirt@cisco.com
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Timeline
No history available yet.