CyberSec.Space Logo
CVEブラウザに戻る

CVE-2019-1974

CRITICAL
9.8
CVSS Severity Score
EPSS Score0.0340%
EPSS Percentile26.95th
Published2019年8月21日
Last Modified2024年11月21日

Vulnerability Description

A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) Supervisor, Cisco UCS Director, and Cisco UCS Director Express for Big Data could allow an unauthenticated, remote attacker to bypass user authentication and gain access as an administrative user. The vulnerability is due to insufficient request header validation during the authentication process. An attacker could exploit this vulnerability by sending a series of malicious requests to an affected device. An exploit could allow the attacker to gain full administrative access to the affected device.

Affected Platforms (CPE)

📦
Cisco

Integrated Management Controller Supervisor

>= 2.2.0.0 and <= 2.2.0.6
📦
Cisco

Integrated Management Controller Supervisor

= 2.1.0.0
📦
Cisco

Ucs Director

>= 5.5.0.0 and <= 5.5.0.2
📦
Cisco

Ucs Director

>= 6.0.0.0 and <= 6.0.1.3
📦
Cisco

Ucs Director

>= 6.5.0.0 and <= 6.5.0.3
📦
Cisco

Ucs Director

>= 6.6.0.0 and <= 6.6.1.0
📦
Cisco

Ucs Director

>= 6.7.0.0 and <= 6.7.2.0
📦
Cisco

Ucs Director

= 6.7\(1.1\)
📦
Cisco

Ucs Director

= 6.7\(2.0\)
📦
Cisco

Ucs Director Express For Big Data

>= 2.1.0.0 and <= 2.1.0.2
📦
Cisco

Ucs Director Express For Big Data

>= 3.0.0.0 and <= 3.0.1.3
📦
Cisco

Ucs Director Express For Big Data

>= 3.5.0.0 and <= 3.5.0.3
📦
Cisco

Ucs Director Express For Big Data

>= 3.7.0.0 and <= 3.7.2.0
📦
Cisco

Ucs Director Express For Big Data

= 3.6.0.0
📦
Cisco

Ucs Director Express For Big Data

= 3.6.1.0

References & Advisories

関連する脆弱性情報