PT-2019-3020 · Cisco · Cisco Ucs Director+2

Published

2019-08-21

·

Updated

2023-03-31

·

CVE-2019-1935

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Cisco Integrated Management Controller (IMC) Supervisor versions (affected versions not specified) Cisco UCS Director versions (affected versions not specified) Cisco UCS Director Express for Big Data versions (affected versions not specified)
Description The issue is related to the presence of a default account with an undocumented default password and incorrect permission settings. This could allow a remote attacker to log in to the command-line interface of an affected system with administrator privileges. The attacker could exploit this by using the scpuser account to log in and execute arbitrary commands, potentially gaining full read and write access to the system's database.
Recommendations For Cisco Integrated Management Controller (IMC) Supervisor, change the default password for the scpuser account and correct the permission settings to prevent unauthorized access. For Cisco UCS Director, change the default password for the scpuser account and correct the permission settings to prevent unauthorized access. For Cisco UCS Director Express for Big Data, change the default password for the scpuser account and correct the permission settings to prevent unauthorized access. As a temporary workaround, consider disabling the scpuser account until a patch is available to prevent exploitation.

Exploit

Fix

Using Hardcoded Credentials

Weakness Enumeration

Related Identifiers

BDU:2019-02999
CVE-2019-1935

Affected Products

Cisco Integrated Management Controller (Imc) Supervisor
Cisco Ucs Director
Cisco Ucs Director Express For Big Data