PT-2019-3022 · Cisco · Cisco Ucs Director+2

Published

2019-08-21

·

Updated

2023-11-03

·

CVE-2019-1937

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Cisco Integrated Management Controller (IMC) Supervisor versions (affected versions not specified) Cisco UCS Director versions (affected versions not specified) Cisco UCS Director Express for Big Data versions (affected versions not specified)
Description A vulnerability in the web-based management interface could allow an unauthenticated, remote attacker to acquire a valid session token with administrator privileges, bypassing user authentication. The issue is due to insufficient request header validation during the authentication process. An attacker could exploit this by sending a series of malicious requests to an affected device, potentially gaining full administrator access.
Recommendations For Cisco Integrated Management Controller (IMC) Supervisor, update to a version that includes the fix for this issue. For Cisco UCS Director, apply the recommended configuration changes to mitigate the risk of exploitation. For Cisco UCS Director Express for Big Data, restrict access to the vulnerable web-based management interface until a patch is available. As a temporary workaround, consider disabling the authentication process until a patch is available. Restrict access to the affected devices to minimize the risk of exploitation.

Exploit

Fix

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2019-03001
CVE-2019-1937

Affected Products

Cisco Integrated Management Controller (Imc) Supervisor
Cisco Ucs Director
Cisco Ucs Director Express For Big Data