CyberSec.Space Logo
CVEブラウザに戻る

CVE-2019-1937

CRITICAL
9.8
CVSS Severity Score
EPSS Score0.0690%
EPSS Percentile38.66th
Published2019年8月21日
Last Modified2024年11月21日

Vulnerability Description

A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) Supervisor, Cisco UCS Director, and Cisco UCS Director Express for Big Data could allow an unauthenticated, remote attacker to acquire a valid session token with administrator privileges, bypassing user authentication. The vulnerability is due to insufficient request header validation during the authentication process. An attacker could exploit this vulnerability by sending a series of malicious requests to an affected device. An exploit could allow the attacker to use the acquired session token to gain full administrator access to the affected device.

Affected Platforms (CPE)

📦
Cisco

Integrated Management Controller Supervisor

>= 2.2.0.3 and <= 2.2.0.6
📦
Cisco

Ucs Director

>= 6.6.0.0 and <= 6.6.1.0
📦
Cisco

Ucs Director

>= 6.7.0.0 and <= 6.7.1.0
📦
Cisco

Ucs Director

= 6.7\(0.0.67265\)
📦
Cisco

Ucs Director Express For Big Data

>= 3.7.0.0 and <= 3.7.1.0
📦
Cisco

Ucs Director Express For Big Data

= 3.6.0.0

References & Advisories

関連する脆弱性情報