CVE-2019-1896
7.2
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Exploitability: 1.2 / Impact: 5.9
Source: NVD
Description
A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) could allow an authenticated, remote attacker to inject arbitrary commands and obtain root privileges. The vulnerability is due to insufficient validation of user-supplied input in the Certificate Signing Request (CSR) function of the web-based management interface. An attacker could exploit this vulnerability by submitting a crafted CSR in the web-based management interface. A successful exploit could allow an attacker with administrator privileges to execute arbitrary commands on the device with full root privileges.
Affected (5)
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Version 4.0(1c)hs3 |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| From 2.0.0.0 to 2.0\(13o\) |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| From 4.0.0.0 to 4.0\(2f\) |
| Running on/with | Platform Versions |
|---|---|
Cisco Encs 5100 | All versions |
Cisco Encs 5400 | All versions |
Cisco Ucs E1120d M3 | All versions |
Cisco Ucs E140s M2 | All versions |
Cisco Ucs E160d M2 | All versions |
Cisco Ucs E160s M3 | All versions |
Cisco Ucs E168d M2 | All versions |
Cisco Ucs E180d M3 | All versions |
Cisco Ucs C125 M5 | All versions |
Cisco Ucs C4200 | All versions |
Cisco Ucs S3260 | All versions |
References (2)
Source: psirt@cisco.com
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Timeline
No history available yet.