PT-2019-3283 · Cisco · Cisco Ucs Fabric Interconnect+3

Published

2019-08-28

·

Updated

2020-10-16

·

CVE-2019-1966

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Cisco UCS Fabric Interconnect Software (affected versions not specified) UCS 6200 Series Fabric Interconnects (affected versions not specified) UCS 6300 Series Fabric Interconnects (affected versions not specified) UCS 6400 Series Fabric Interconnects (affected versions not specified)
Description A vulnerability in the local management context of Cisco UCS Fabric Interconnect Software could allow an authenticated, local attacker to gain elevated privileges as the root user on an affected device. The issue is due to extraneous subcommand options present for a specific CLI command within the local-mgmt context. An attacker could exploit this by authenticating to the device, entering the local-mgmt context, and issuing a specific CLI command with user input. A successful exploit could allow the attacker to execute arbitrary operating system commands as root.
Recommendations For Cisco UCS Fabric Interconnect Software, consider restricting access to the local-mgmt context until a fix is available. For UCS 6200 Series Fabric Interconnects, UCS 6300 Series Fabric Interconnects, and UCS 6400 Series Fabric Interconnects, restrict the use of the vulnerable CLI command in the local-mgmt context to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2019-03306
CVE-2019-1966

Affected Products

Cisco Ucs Fabric Interconnect
Ucs 6200 Series Fabric Interconnects
Ucs 6300 Series Fabric Interconnects
Cisco Ucs 6400 Series Fabric Interconnects