CVE-2019-1908
published 2019-08-21CVE-2019-1908: A vulnerability in the Intelligent Platform Management Interface (IPMI) implementation of Cisco Integrated Management Controller (IMC) could allow an…
PriorityP344high7.5CVSS 3.1
AVNACLPRNUINSUCHINAN
EPSS
2.00%
78.4th percentile
A vulnerability in the Intelligent Platform Management Interface (IPMI) implementation of Cisco Integrated Management Controller (IMC) could allow an unauthenticated, remote attacker to view sensitive system information. The vulnerability is due to insufficient security restrictions imposed by the affected software. A successful exploit could allow the attacker to view sensitive information that belongs to other users. The attacker could then use this information to conduct additional attacks.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | cisco_unified_computing_system | >= unspecified < 3.0(4k) | 3.0(4k) |
| cisco | integrated_management_controller | — | — |
| cisco | integrated_management_controller_supervisor | >= 2.0.0.0 < 2.0\(13o\) | 2.0\(13o\) |
| cisco | integrated_management_controller_supervisor | >= 3.0.0.0 < 3.0\(4k\) | 3.0\(4k\) |
| cisco | integrated_management_controller_supervisor | >= 4.0.0.0 < 4.0\(4b\) | 4.0\(4b\) |
| cisco | integrated_management_controller_supervisor | >= 4.0.0.0 < 4.0\(2f\) | 4.0\(2f\) |
| cisco | unified_computing_system | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
vendor_redhat9.8CRITICAL
vendor_cisco7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-m28c-69j7-79gf: A vulnerability in the Intelligent Platform Management Interface (IPMI) implementation of Cisco Integrated Management Controller (IMC) could allow an
ghsa_unreviewed·2022-05-24
CVE-2019-1908 [HIGH] GHSA-m28c-69j7-79gf: A vulnerability in the Intelligent Platform Management Interface (IPMI) implementation of Cisco Integrated Management Controller (IMC) could allow an
A vulnerability in the Intelligent Platform Management Interface (IPMI) implementation of Cisco Integrated Management Controller (IMC) could allow an unauthenticated, remote attacker to view sensitive system information. The vulnerability is due to insufficient security restrictions imposed by the affected software. A successful exploit could allow the attacker to view sensitive information that belongs to other users. The attacker could then use this information to conduct additional attacks.
Red Hat
rsyslog: heap-based overflow in contrib/pmcisconames/pmcisconames.c
vendor_redhat·2019-10-01·CVSS 9.8
CVE-2019-17042 [CRITICAL] CWE-122 rsyslog: heap-based overflow in contrib/pmcisconames/pmcisconames.c
rsyslog: heap-based overflow in contrib/pmcisconames/pmcisconames.c
An issue was discovered in Rsyslog v8.1908.0. contrib/pmcisconames/pmcisconames.c has a heap overflow in the parser for Cisco log messages. The parser tries to locate a log message delimiter (in this case, a space or a colon), but fails to account for strings that do not satisfy this constraint. If the string does not match, then the variable lenMsg will reach the value zero and will skip the sanity check that detects invalid log messages. The message will then be considered valid, and the parser will eat up the nonexistent colon delimiter. In doing so, it will decrement lenMsg, a signed integer, whose value was zero and now becomes minus one. The following step in the parser is to shift left the contents of the message.
Red Hat
rsyslog: heap-based overflow in contrib/pmaixforwardedfrom/pmaixforwardedfrom.c
vendor_redhat·2019-09-30·CVSS 9.8
CVE-2019-17041 [CRITICAL] CWE-122 rsyslog: heap-based overflow in contrib/pmaixforwardedfrom/pmaixforwardedfrom.c
rsyslog: heap-based overflow in contrib/pmaixforwardedfrom/pmaixforwardedfrom.c
An issue was discovered in Rsyslog v8.1908.0. contrib/pmaixforwardedfrom/pmaixforwardedfrom.c has a heap overflow in the parser for AIX log messages. The parser tries to locate a log message delimiter (in this case, a space or a colon) but fails to account for strings that do not satisfy this constraint. If the string does not match, then the variable lenMsg will reach the value zero and will skip the sanity check that detects invalid log messages. The message will then be considered valid, and the parser will eat up the nonexistent colon delimiter. In doing so, it will decrement lenMsg, a signed integer, whose value was zero and now becomes minus one. The following step in the parser is to shift left the cont
Red Hat
rsyslog: out-of-bounds read in contrib/pmdb2diag/pmdb2diag.c
vendor_redhat·2019-09-24·CVSS 9.8
CVE-2019-17040 [CRITICAL] rsyslog: out-of-bounds read in contrib/pmdb2diag/pmdb2diag.c
rsyslog: out-of-bounds read in contrib/pmdb2diag/pmdb2diag.c
contrib/pmdb2diag/pmdb2diag.c in Rsyslog v8.1908.0 allows out-of-bounds access because the level length is mishandled.
Package: rsyslog (Red Hat Enterprise Linux 5) - Not affected
Package: rsyslog5 (Red Hat Enterprise Linux 5) - Not affected
Package: rsyslog (Red Hat Enterprise Linux 6) - Not affected
Package: rsyslog7 (Red Hat Enterprise Linux 6) - Not affected
Package: rsyslog (Red Hat Enterprise Linux 7) - Not affected
Package: rsyslog (Red Hat Enterprise Linux 8) - Not affected
Cisco
Cisco Integrated Management Controller Information Disclosure Vulnerability
vendor_cisco·2019-08-21·CVSS 7.5
CVE-2019-1908 [HIGH] CWE-200 Cisco Integrated Management Controller Information Disclosure Vulnerability
Cisco Integrated Management Controller Information Disclosure Vulnerability
A vulnerability in the Intelligent Platform Management Interface (IPMI) implementation of Cisco Integrated Management Controller (IMC) could allow an unauthenticated, remote attacker to view sensitive system information.
The vulnerability is due to insufficient security restrictions imposed by the affected software. A successful exploit could allow the attacker to view sensitive information that belongs to other users. The attacker could then use this information to conduct additional attacks.
Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.
This advisory is available at the following link:
https://sec.cloudapps.cisco.com/security/center
Cisco
Cisco Integrated Management Controller Information Disclosure Vulnerability
vendor_cisco·CVSS 3.0
CVE-2019-1908 Cisco Integrated Management Controller Information Disclosure Vulnerability
CVE-2019-1908: Cisco Integrated Management Controller Information Disclosure Vulnerability
A vulnerability in the Intelligent Platform Management Interface (IPMI) implementation of Cisco Integrated Management Controller (IMC) could allow an unauthenticated, remote attacker to view sensitive system information. The vulnerability is due to insufficient security restrictions imposed by the affected software. A successful exploit could allow the attacker to view sensitive information that belongs to other users. The attacker could then use this information to conduct additional attacks. Cisco has released software updates that address this vulnerability. There are no
CVSS: 3.0
CWE: CWE-200, CWE-200
Bug IDs: CSCvo36096
No detection rules found.
Tenable
Critical Cisco Vulnerabilities Across Multiple Products, Exploit Code for CVE-2019-1913 Reportedly Released
blogs_tenable·2019-08-22·CVSS 9.8
[CRITICAL] Critical Cisco Vulnerabilities Across Multiple Products, Exploit Code for CVE-2019-1913 Reportedly Released
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Bugzilla
CVE-2019-17040 rsyslog: out-of-bounds read in contrib/pmdb2diag/pmdb2diag.c
bugzilla·2019-10-29·CVSS 9.8
CVE-2019-17040 [CRITICAL] CVE-2019-17040 rsyslog: out-of-bounds read in contrib/pmdb2diag/pmdb2diag.c
CVE-2019-17040 rsyslog: out-of-bounds read in contrib/pmdb2diag/pmdb2diag.c
contrib/pmdb2diag/pmdb2diag.c in Rsyslog v8.1908.0 allows out-of-bounds access because the level length is mishandled.
Reference:
https://github.com/rsyslog/rsyslog/pull/3875
Discussion:
Created rsyslog tracking bugs for this issue:
Affects: fedora-all [bug 1766642]
---
Upstream commit: https://github.com/rsyslog/rsyslog/pull/3875/commits/b0894088b680666035a3418326e13bc99d4fed49
---
This flaw affects the pmdb2diag.c code file which was introduced in rsyslog-8.1903.0 which was released on 2019-03-05. Older versions of rsyslog are not affected by this flaw.
Bugzilla
CVE-2019-17041 rsyslog: heap-based overflow in contrib/pmaixforwardedfrom/pmaixforwardedfrom.c
bugzilla·2019-10-29·CVSS 9.8
CVE-2019-17041 [CRITICAL] CVE-2019-17041 rsyslog: heap-based overflow in contrib/pmaixforwardedfrom/pmaixforwardedfrom.c
CVE-2019-17041 rsyslog: heap-based overflow in contrib/pmaixforwardedfrom/pmaixforwardedfrom.c
An issue was discovered in Rsyslog v8.1908.0. contrib/pmaixforwardedfrom/pmaixforwardedfrom.c has a heap overflow in the parser for AIX log messages. The parser tries to locate a log message delimiter (in this case, a space or a colon) but fails to account for strings that do not satisfy this constraint. If the string does not match, then the variable lenMsg will reach the value zero and will skip the sanity check that detects invalid log messages. The message will then be considered valid, and the parser will eat up the nonexistent colon delimiter. In doing so, it will decrement lenMsg, a signed integer, whose value was zero and now becomes minus one. The following step in the parser is to shif
2019-08-21
Published