CVE-2019-1865
published 2019-08-21CVE-2019-1865: A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) Software could allow an authenticated, remote attacker to…
PriorityP261high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
3.57%
88.1th percentile
A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) Software could allow an authenticated, remote attacker to inject arbitrary commands that are executed with root privileges on an affected device. The vulnerability is due to insufficient validation of user-supplied input by the affected software. An attacker could exploit this vulnerability by invoking an interface monitoring mechanism with a crafted argument on the affected software. A successful exploit could allow the attacker to inject and execute arbitrary, system-level commands with root privileges on an affected device.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | cisco_unified_computing_system_e-series_software | >= unspecified < 2.0(13o) | 2.0(13o) |
| cisco | integrated_management_controller | — | — |
| cisco | integrated_management_controller_supervisor | >= 1.5.0.0 < 1.5\(9g\) | 1.5\(9g\) |
| cisco | integrated_management_controller_supervisor | >= 2.0.0.0 < 2.0\(13o\) | 2.0\(13o\) |
| cisco | integrated_management_controller_supervisor | >= 3.0.0.0 < 3.0\(4k\) | 3.0\(4k\) |
| cisco | integrated_management_controller_supervisor | >= 4.0.0.0 < 4.0\(4b\) | 4.0\(4b\) |
| cisco | integrated_management_controller_supervisor | >= 4.0.0.0 < 4.0\(1d\) | 4.0\(1d\) |
| cisco | integrated_management_controller_supervisor | >= 4.0.0.0 < 4.0\(2c\) | 4.0\(2c\) |
| cisco | unified_computing_system | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Exploitation requires an authenticated attacker to invoke an interface monitoring mechanism with a crafted argument via the web-based management interface of Cisco IMC, resulting in root-level command injection (CWE-78). ↗
- →Successful exploitation results in arbitrary system-level commands executed with root privileges — monitor Cisco IMC web management interface for anomalous privileged process spawning. ↗
- →Track Cisco Bug ID CSCvn20993 for patch and affected version details relevant to this vulnerability. ↗
- ·Exploitation requires prior authentication to the Cisco IMC web-based management interface; unauthenticated remote exploitation is not possible. ↗
- ·No workarounds are available; detection/prevention relies on patching or network-level access control to the IMC management interface. ↗
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv3.08.8HIGHCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.09.0CRITICALAV:N/AC:L/Au:S/C:C/I:C/A:C
vendor_cisco8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-3xrf-vrqp-mvm5: A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) Software could allow an authenticated, remote at
ghsa_unreviewed·2022-05-24
CVE-2019-1865 [HIGH] CWE-78 GHSA-3xrf-vrqp-mvm5: A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) Software could allow an authenticated, remote at
A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) Software could allow an authenticated, remote attacker to inject arbitrary commands that are executed with root privileges on an affected device. The vulnerability is due to insufficient validation of user-supplied input by the affected software. An attacker could exploit this vulnerability by invoking an interface monitoring mechanism with a crafted argument on the affected software. A successful exploit could allow the attacker to inject and execute arbitrary, system-level commands with root privileges on an affected device.
Cisco
Cisco Integrated Management Controller Command Injection Vulnerability
vendor_cisco·2019-08-21·CVSS 8.8
CVE-2019-1865 [HIGH] CWE-78 Cisco Integrated Management Controller Command Injection Vulnerability
Cisco Integrated Management Controller Command Injection Vulnerability
A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) Software could allow an authenticated, remote attacker to inject arbitrary commands that are executed with root privileges on an affected device.
The vulnerability is due to insufficient validation of user-supplied input by the affected software. An attacker could exploit this vulnerability by invoking an interface monitoring mechanism with a crafted argument on the affected software. A successful exploit could allow the attacker to inject and execute arbitrary, system-level commands with root privileges on an affected device.
Cisco has released software updates that address this vulnerability. There are no workarounds
Cisco
Cisco Integrated Management Controller Command Injection Vulnerability
vendor_cisco·CVSS 3.0
CVE-2019-1865 Cisco Integrated Management Controller Command Injection Vulnerability
CVE-2019-1865: Cisco Integrated Management Controller Command Injection Vulnerability
A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) Software could allow an authenticated, remote attacker to inject arbitrary commands that are executed with root privileges on an affected device. The vulnerability is due to insufficient validation of user-supplied input by the affected software. An attacker could exploit this vulnerability by invoking an interface monitoring mechanism with a crafted argument on the affected software. A successful exploit could allow the attacker to inject and execute arbitrary, system-level commands with root privileges on an affected device. Cisco has released software updates that address this vulnerability. There are
No detection rules found.
No public exploits indexed.
2019-08-21
Published