CVE-2019-1896
published 2019-08-21CVE-2019-1896: A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) could allow an authenticated, remote attacker to inject…
PriorityP348high7.2CVSS 3.1
AVNACLPRHUINSUCHIHAH
EPSS
1.82%
76.3th percentile
A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) could allow an authenticated, remote attacker to inject arbitrary commands and obtain root privileges. The vulnerability is due to insufficient validation of user-supplied input in the Certificate Signing Request (CSR) function of the web-based management interface. An attacker could exploit this vulnerability by submitting a crafted CSR in the web-based management interface. A successful exploit could allow an attacker with administrator privileges to execute arbitrary commands on the device with full root privileges.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | cisco_unified_computing_system_e-series_software | >= unspecified < 3.0(4k) | 3.0(4k) |
| cisco | integrated_management_controller_csr_generation | — | — |
| cisco | integrated_management_controller_supervisor | >= 2.0.0.0 < 2.0\(13o\) | 2.0\(13o\) |
| cisco | integrated_management_controller_supervisor | >= 3.0.0.0 < 3.0\(4k\) | 3.0\(4k\) |
| cisco | integrated_management_controller_supervisor | >= 4.0.0.0 < 4.0\(4b\) | 4.0\(4b\) |
| cisco | integrated_management_controller_supervisor | >= 4.0.0.0 < 4.0\(2f\) | 4.0\(2f\) |
| cisco | unified_computing_system | — | — |
CVSS provenance
nvdv3.17.2HIGHCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
nvdv3.07.2HIGHCVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
nvdv2.09.0CRITICALAV:N/AC:L/Au:S/C:C/I:C/A:C
vendor_cisco7.2HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-ch4g-7fmw-mr53: A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) could allow an authenticated, remote attacker to
ghsa_unreviewed·2022-05-24
CVE-2019-1896 [HIGH] CWE-78 GHSA-ch4g-7fmw-mr53: A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) could allow an authenticated, remote attacker to
A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) could allow an authenticated, remote attacker to inject arbitrary commands and obtain root privileges. The vulnerability is due to insufficient validation of user-supplied input in the Certificate Signing Request (CSR) function of the web-based management interface. An attacker could exploit this vulnerability by submitting a crafted CSR in the web-based management interface. A successful exploit could allow an attacker with administrator privileges to execute arbitrary commands on the device with full root privileges.
Cisco
Cisco Integrated Management Controller CSR Generation Command Injection Vulnerability
vendor_cisco·2019-08-21·CVSS 7.2
CVE-2019-1896 [HIGH] CWE-78 Cisco Integrated Management Controller CSR Generation Command Injection Vulnerability
Cisco Integrated Management Controller CSR Generation Command Injection Vulnerability
A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) could allow an authenticated, remote attacker to inject arbitrary commands and obtain root privileges.
The vulnerability is due to insufficient validation of user-supplied input in the Certificate Signing Request (CSR) function of the web-based management interface. An attacker could exploit this vulnerability by submitting a crafted CSR in the web-based management interface. A successful exploit could allow an attacker with administrator privileges to execute arbitrary commands on the device with full root privileges.
Cisco has released software updates that address this vulnerability. There are no wor
Cisco
Cisco Integrated Management Controller CSR Generation Command Injection Vulnerability
vendor_cisco·CVSS 3.0
CVE-2019-1896 Cisco Integrated Management Controller CSR Generation Command Injection Vulnerability
CVE-2019-1896: Cisco Integrated Management Controller CSR Generation Command Injection Vulnerability
A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) could allow an authenticated, remote attacker to inject arbitrary commands and obtain root privileges. The vulnerability is due to insufficient validation of user-supplied input in the Certificate Signing Request (CSR) function of the web-based management interface. An attacker could exploit this vulnerability by submitting a crafted CSR in the web-based management interface. A successful exploit could allow an attacker with administrator privileges to execute arbitrary commands on the device with full root privileges. Cisco has released software updates that address this vulnerability. The
No detection rules found.
No public exploits indexed.
2019-08-21
Published