← Back

CVE-2019-1900

nvd nist
Published: Aug 21, 2019Modified: Jun 17, 2026

JSON object

Loading...
7.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Exploitability: 3.9 / Impact: 3.6
Source: NVD

Description

A vulnerability in the web server of Cisco Integrated Management Controller (IMC) could allow an unauthenticated, remote attacker to cause the web server process to crash, causing a denial of service (DoS) condition on an affected system. The vulnerability is due to insufficient validation of user-supplied input on the web interface. An attacker could exploit this vulnerability by submitting a crafted HTTP request to certain endpoints of the affected software. A successful exploit could allow an attacker to cause the web server to crash. Physical access to the device may be required for a restart.

Affected (2)

2 products
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 4.0(1c)hs3
Configuration B
1 vulnerable · 3 platform
Vulnerable SoftwareAffected Versions
From 4.0.0.0 to 4.0\(2f\)
Running on/withPlatform Versions
Cisco
Ucs C125 M5
All versions
Cisco
Ucs C4200
All versions
Cisco
Ucs S3260
All versions

Timeline

No history available yet.