CVE-2019-1629
published 2019-06-20CVE-2019-1629: A vulnerability in the configuration import utility of Cisco Integrated Management Controller (IMC) could allow an unauthenticated, remote attacker to have…
PriorityP335medium5.3CVSS 3.0
AVNACLPRNUINSUCNILAN
EPSS
1.52%
71.7th percentile
A vulnerability in the configuration import utility of Cisco Integrated Management Controller (IMC) could allow an unauthenticated, remote attacker to have write access and upload arbitrary data to the filesystem. The vulnerability is due to a failure to delete temporarily uploaded files. An attacker could exploit this vulnerability by crafting a malicious file and uploading it to the affected device. An exploit could allow the attacker to fill up the filesystem or upload malicious scripts.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | cisco_unified_computing_system | — | — |
| cisco | integrated_management_controller | — | — |
| cisco | unified_computing_system | — | — |
CVSS provenance
nvdv3.05.3MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
vendor_cisco5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-2xqf-m93c-8p52: A vulnerability in the configuration import utility of Cisco Integrated Management Controller (IMC) could allow an unauthenticated, remote attacker to
ghsa_unreviewed·2022-05-24
CVE-2019-1629 [MEDIUM] CWE-306 GHSA-2xqf-m93c-8p52: A vulnerability in the configuration import utility of Cisco Integrated Management Controller (IMC) could allow an unauthenticated, remote attacker to
A vulnerability in the configuration import utility of Cisco Integrated Management Controller (IMC) could allow an unauthenticated, remote attacker to have write access and upload arbitrary data to the filesystem. The vulnerability is due to a failure to delete temporarily uploaded files. An attacker could exploit this vulnerability by crafting a malicious file and uploading it to the affected device. An exploit could allow the attacker to fill up the filesystem or upload malicious scripts.
Cisco
Cisco Integrated Management Controller Arbitrary File Write Vulnerability
vendor_cisco·2019-06-19·CVSS 5.3
CVE-2019-1629 [MEDIUM] CWE-306 Cisco Integrated Management Controller Arbitrary File Write Vulnerability
Cisco Integrated Management Controller Arbitrary File Write Vulnerability
A vulnerability in the configuration import utility of Cisco Integrated Management Controller (IMC) could allow an unauthenticated, remote attacker to have write access and upload arbitrary data to the filesystem.
The vulnerability is due to a failure to delete temporarily uploaded files. An attacker could exploit this vulnerability by crafting a malicious file and uploading it to the affected device. An exploit could allow the attacker to fill up the filesystem or upload malicious scripts.
There are no workarounds that address this vulnerability.
This advisory is available at the following link:
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190619-imc-filewrite
Cisco
Cisco Integrated Management Controller Arbitrary File Write Vulnerability
vendor_cisco·CVSS 3.0
CVE-2019-1629 Cisco Integrated Management Controller Arbitrary File Write Vulnerability
CVE-2019-1629: Cisco Integrated Management Controller Arbitrary File Write Vulnerability
A vulnerability in the configuration import utility of Cisco Integrated Management Controller (IMC) could allow an unauthenticated, remote attacker to have write access and upload arbitrary data to the filesystem. The vulnerability is due to a failure to delete temporarily uploaded files. An attacker could exploit this vulnerability by crafting a malicious file and uploading it to the affected device. An exploit could allow the attacker to fill up the filesystem or upload malicious scripts. There are no
CVSS: 3.0
CWE: CWE-306, CWE-306
Bug IDs: CSCvo35982
No detection rules found.
2019-06-20
Published