CVE-2019-1883
published 2019-08-21CVE-2019-1883: A vulnerability in the command-line interface of Cisco Integrated Management Controller (IMC) could allow an authenticated, local attacker with read-only…
PriorityP344high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.41%
33.6th percentile
A vulnerability in the command-line interface of Cisco Integrated Management Controller (IMC) could allow an authenticated, local attacker with read-only credentials to inject arbitrary commands that could allow them to obtain root privileges. The vulnerability is due to insufficient validation of user-supplied input on the command-line interface. An attacker could exploit this vulnerability by authenticating with read-only privileges via the CLI of an affected device and submitting crafted input to the affected commands. A successful exploit could allow an attacker to execute arbitrary commands on the device with root privileges.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | cisco_unified_computing_system_e-series_software | >= unspecified < 3.0(4k) | 3.0(4k) |
| cisco | integrated_management_controller | — | — |
| cisco | integrated_management_controller_supervisor | >= 3.0.0.0 < 3.0\(4k\) | 3.0\(4k\) |
| cisco | integrated_management_controller_supervisor | >= 4.0.0.0 < 4.0\(4b\) | 4.0\(4b\) |
| cisco | integrated_management_controller_supervisor | >= 4.0.0.0 < 4.0\(2f\) | 4.0\(2f\) |
| cisco | unified_computing_system | — | — |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv3.07.0HIGHCVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
vendor_cisco7.0HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-2fxw-qpjx-9wpm: A vulnerability in the command-line interface of Cisco Integrated Management Controller (IMC) could allow an authenticated, local attacker with read-o
ghsa_unreviewed·2022-05-24
CVE-2019-1883 [HIGH] CWE-78 GHSA-2fxw-qpjx-9wpm: A vulnerability in the command-line interface of Cisco Integrated Management Controller (IMC) could allow an authenticated, local attacker with read-o
A vulnerability in the command-line interface of Cisco Integrated Management Controller (IMC) could allow an authenticated, local attacker with read-only credentials to inject arbitrary commands that could allow them to obtain root privileges. The vulnerability is due to insufficient validation of user-supplied input on the command-line interface. An attacker could exploit this vulnerability by authenticating with read-only privileges via the CLI of an affected device and submitting crafted input to the affected commands. A successful exploit could allow an attacker to execute arbitrary commands on the device with root privileges.
Cisco
Cisco Integrated Management Controller CLI Command Injection Vulnerability
vendor_cisco·2019-08-21·CVSS 7.0
CVE-2019-1883 [HIGH] CWE-78 Cisco Integrated Management Controller CLI Command Injection Vulnerability
Cisco Integrated Management Controller CLI Command Injection Vulnerability
A vulnerability in the command-line interface of Cisco Integrated Management Controller (IMC) could allow an authenticated, local attacker with read-only credentials to inject arbitrary commands that could allow them to obtain root privileges.
The vulnerability is due to insufficient validation of user-supplied input on the command-line interface. An attacker could exploit this vulnerability by authenticating with read-only privileges via the CLI of an affected device and submitting crafted input to the affected commands. A successful exploit could allow an attacker to execute arbitrary commands on the device with root privileges.
Cisco has released software updates that address this vulnerability. There are no wor
Cisco
Cisco Integrated Management Controller CLI Command Injection Vulnerability
vendor_cisco·CVSS 3.0
CVE-2019-1883 Cisco Integrated Management Controller CLI Command Injection Vulnerability
CVE-2019-1883: Cisco Integrated Management Controller CLI Command Injection Vulnerability
A vulnerability in the command-line interface of Cisco Integrated Management Controller (IMC) could allow an authenticated, local attacker with read-only credentials to inject arbitrary commands that could allow them to obtain root privileges. The vulnerability is due to insufficient validation of user-supplied input on the command-line interface. An attacker could exploit this vulnerability by authenticating with read-only privileges via the CLI of an affected device and submitting crafted input to the affected commands. A successful exploit could allow an attacker to execute arbitrary commands on the device with root privileges. Cisco has released software updates that address this vulnerability. Th
No detection rules found.
No public exploits indexed.
2019-08-21
Published