cbcvebase.
CVE-2019-1908
published 2019-08-21

CVE-2019-1908: A vulnerability in the Intelligent Platform Management Interface (IPMI) implementation of Cisco Integrated Management Controller (IMC) could allow an…

PriorityP344high7.5CVSS 3.1
AVNACLPRNUINSUCHINAN
EPSS
2.00%
78.4th percentile
A vulnerability in the Intelligent Platform Management Interface (IPMI) implementation of Cisco Integrated Management Controller (IMC) could allow an unauthenticated, remote attacker to view sensitive system information. The vulnerability is due to insufficient security restrictions imposed by the affected software. A successful exploit could allow the attacker to view sensitive information that belongs to other users. The attacker could then use this information to conduct additional attacks.

Affected

7 ranges
VendorProductVersion rangeFixed in
ciscocisco_unified_computing_system>= unspecified < 3.0(4k)3.0(4k)
ciscointegrated_management_controller
ciscointegrated_management_controller_supervisor>= 2.0.0.0 < 2.0\(13o\)2.0\(13o\)
ciscointegrated_management_controller_supervisor>= 3.0.0.0 < 3.0\(4k\)3.0\(4k\)
ciscointegrated_management_controller_supervisor>= 4.0.0.0 < 4.0\(4b\)4.0\(4b\)
ciscointegrated_management_controller_supervisor>= 4.0.0.0 < 4.0\(2f\)4.0\(2f\)
ciscounified_computing_system

CVSS provenance

nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
vendor_redhat9.8CRITICAL
vendor_cisco7.5HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.