CVE-2019-1935
published 2019-08-21CVE-2019-1935: A vulnerability in Cisco Integrated Management Controller (IMC) Supervisor, Cisco UCS Director, and Cisco UCS Director Express for Big Data could allow an…
PriorityP186critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EXPLOIT
EPSS
83.39%
99.7th percentile
A vulnerability in Cisco Integrated Management Controller (IMC) Supervisor, Cisco UCS Director, and Cisco UCS Director Express for Big Data could allow an unauthenticated, remote attacker to log in to the CLI of an affected system by using the SCP User account (scpuser), which has default user credentials. The vulnerability is due to the presence of a documented default account with an undocumented default password and incorrect permission settings for that account. Changing the default password for this account is not enforced during the installation of the product. An attacker could exploit this vulnerability by using the account to log in to an affected system. A successful exploit could allow the attacker to execute arbitrary commands with the privileges of the scpuser account. This includes full read and write access to the system's database.
Affected
17 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | tomcat | — | — |
| cisco | cisco_unified_computing_system_director | >= unspecified < 6.7.3.0 | 6.7.3.0 |
| cisco | integrated_management_controller_supervisor | — | — |
| cisco | integrated_management_controller_supervisor | 2.2.0.0 – 2.2.0.6 | — |
| cisco | integrated_management_controller_supervisor_cisco_ucs_director_and_cisco_ucs_dir | — | — |
| cisco | ucs_director | — | — |
| cisco | ucs_director | — | — |
| cisco | ucs_director | — | — |
| cisco | ucs_director | — | — |
| cisco | ucs_director | — | — |
| cisco | ucs_director | — | — |
| cisco | ucs_director | — | — |
| cisco | ucs_director_express_for_big_data | — | — |
| cisco | ucs_director_express_for_big_data | — | — |
| cisco | ucs_director_express_for_big_data | — | — |
| cisco | ucs_director_express_for_big_data | — | — |
| cisco | ucs_director_express_for_big_data | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Detect SSH login attempts using the username 'scpuser' — the default credential pair is scpuser:scpuser. Alert on successful SSH authentication with this account. ↗
- →Detect HTTP requests to /app/ui/ClientServlet that include both X-Starship-UserSession-Key and X-Starship-Request-Key headers simultaneously — this is the authentication bypass pattern for CVE-2019-1937 (related, same advisory). ↗
- →Monitor for SSH sessions on port 22 to Cisco UCS Director / IMC Supervisor appliances originating from unexpected sources, particularly those authenticating with password-based auth methods. ↗
- →Alert on HTTP responses from /app/ui/ClientServlet returning loginName 'admin' without a prior valid authentication flow — indicates successful auth bypass. ↗
- ·The default password for the scpuser account is not enforced to be changed during product installation, meaning vulnerable systems may remain exposed post-deployment without active remediation. ↗
- ·The Metasploit module was only tested against Cisco UCS Director versions 6.6.0 and 6.7.0; IMC Supervisor and UCS Director Express for Big Data are listed as affected by Cisco but were not independently verified by the researcher. ↗
- ·The scpuser account grants full read and write access to the system's database, not just limited shell access — privilege scope is broader than a typical unprivileged account. ↗
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv3.09.8CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
vendor_cisco9.8CRITICAL
vendor_apache4.8MEDIUM
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco Integrated Management Controller Supervisor, Cisco UCS Director, and Cisco UCS Director Express for Big Data SCP User Default Credentials Vulnerability
vendor_cisco·2019-08-21·CVSS 9.8
CVE-2019-1935 [CRITICAL] CWE-798 Cisco Integrated Management Controller Supervisor, Cisco UCS Director, and Cisco UCS Director Express for Big Data SCP User Default Credentials Vulnerability
Cisco Integrated Management Controller Supervisor, Cisco UCS Director, and Cisco UCS Director Express for Big Data SCP User Default Credentials Vulnerability
A vulnerability in Cisco Integrated Management Controller (IMC) Supervisor, Cisco UCS Director, and Cisco UCS Director Express for Big Data could allow an unauthenticated, remote attacker to log in to the CLI of an affected system by using the SCP User account (scpuser), which has default user credentials.
The vulnerability is due to the presence of a documented default account with an undocumented default password and incorrect permission settings for that account. Changing the default password for this account is not enforced during the installation of the product. An attacker could exploit this vulnerability by using the account t
Cisco
Cisco Integrated Management Controller Supervisor, Cisco UCS Director, and Cisco UCS Director Express for Big Data SCP User Default Credentials Vulnerability
vendor_cisco·CVSS 3.0
CVE-2019-1935 Cisco Integrated Management Controller Supervisor, Cisco UCS Director, and Cisco UCS Director Express for Big Data SCP User Default Credentials Vulnerability
CVE-2019-1935: Cisco Integrated Management Controller Supervisor, Cisco UCS Director, and Cisco UCS Director Express for Big Data SCP User Default Credentials Vulnerability
A vulnerability in Cisco Integrated Management Controller (IMC) Supervisor, Cisco UCS Director, and Cisco UCS Director Express for Big Data could allow an unauthenticated, remote attacker to log in to the CLI of an affected system by using the SCP User account ( scpuser ), which has default user credentials. The vulnerability is due to the presence of a documented default account with an undocumented default password and incorrect permission settings for that account. Changing the default password for this account is not enforced during the installation of the product. An attacker could exploit this vulnerability by usi
Apache
Apache tomcat: CVE-2020-1935
vendor_apache·CVSS 4.8
CVE-2020-1935 [MEDIUM] Apache tomcat: CVE-2020-1935
Apache tomcat: CVE-2020-1935
The HTTP header parsing code used an approach to end-of-line (EOL) parsing that allowed some invalid HTTP headers to be parsed as valid. This led to a possibility of HTTP Request Smuggling if Tomcat was located behind a reverse proxy that incorrectly handled the invalid Transfer-Encoding header in a particular manner. Such a reverse proxy is considered unlikely. This was fixed with commit 8fbe2e96 . This issue was reported to the Apache Tomcat Security Team by @ZeddYu on 25 December 2019. The issue was made public on 24 February 2020. Affects: 8.5.0 to 8.5.50 Low: HTTP Request Smuggling
GHSA
GHSA-c9g8-fgq6-h2wg: A vulnerability in Cisco Integrated Management Controller (IMC) Supervisor, Cisco UCS Director, and Cisco UCS Director Express for Big Data could allo
ghsa_unreviewed·2022-05-24
CVE-2019-1935 [CRITICAL] CWE-798 GHSA-c9g8-fgq6-h2wg: A vulnerability in Cisco Integrated Management Controller (IMC) Supervisor, Cisco UCS Director, and Cisco UCS Director Express for Big Data could allo
A vulnerability in Cisco Integrated Management Controller (IMC) Supervisor, Cisco UCS Director, and Cisco UCS Director Express for Big Data could allow an unauthenticated, remote attacker to log in to the CLI of an affected system by using the SCP User account (scpuser), which has default user credentials. The vulnerability is due to the presence of a documented default account with an undocumented default password and incorrect permission settings for that account. Changing the default password for this account is not enforced during the installation of the product. An attacker could exploit this vulnerability by using the account to log in to an affected system. A successful exploit could allow the attacker to execute arbitrary commands with the privileges of the scpuser account. This in
No detection rules found.
Exploit-DB
Cisco UCS Director - default scpuser password (Metasploit)
exploitdb·2019-09-03
CVE-2019-1935 Cisco UCS Director - default scpuser password (Metasploit)
Cisco UCS Director - default scpuser password (Metasploit)
---
##
# This module requires Metasploit: https://metasploit.com/download
# Current source: https://github.com/rapid7/metasploit-framework
##
require 'net/ssh'
require 'net/ssh/command_stream'
class MetasploitModule "Cisco UCS Director default scpuser password",
'Description' => %q{
This module abuses a known default password on Cisco UCS Director. The 'scpuser'
has the password of 'scpuser', and allows an attacker to login to the virtual appliance
via SSH.
This module has been tested with Cisco UCS Director virtual machines 6.6.0 and 6.7.0.
Note that Cisco also mentions in their advisory that their IMC Supervisor and
UCS Director Express are also affected by these vulnerabilities, but this module
was not tested with those prod
Exploit-DB
Cisco UCS Director_ Cisco Integrated Management Controller Supervisor and Cisco UCS Director Express for Big Data - Multiple Vulnerabilities
exploitdb·2019-08-21
Cisco UCS Director_ Cisco Integrated Management Controller Supervisor and Cisco UCS Director Express for Big Data - Multiple Vulnerabilities
Cisco UCS Director_ Cisco Integrated Management Controller Supervisor and Cisco UCS Director Express for Big Data - Multiple Vulnerabilities
---
>> Multiple critical vulnerabilities in Cisco UCS Director, Cisco Integrated Management Controller Supervisor and Cisco UCS Director Express for Big Data
>> Discovered by Pedro Ribeiro ([email protected]) from Agile Information Security
Disclosure: 21/08/2019 / Last updated: 22/08/2019
>> Executive summary:
Cisco UCS Director (UCS) is a cloud orchestration product that automates common private cloud infrastructure management functions. It is built using Java and a variety of other technologies and distributed as a Linux based virtual appliance. A demo of the UCS virtual appliance can be freely downloaded from Cisco's website [1].
Due to severa
Metasploit
Cisco UCS Director default scpuser password
metasploit
Cisco UCS Director default scpuser password
Cisco UCS Director default scpuser password
This module abuses a known default password on Cisco UCS Director. The 'scpuser' has the password of 'scpuser', and allows an attacker to login to the virtual appliance via SSH. This module has been tested with Cisco UCS Director virtual machines 6.6.0 and 6.7.0. Note that Cisco also mentions in their advisory that their IMC Supervisor and UCS Director Express are also affected by these vulnerabilities, but this module was not tested with those products.
Tenable
Critical Cisco Vulnerabilities Across Multiple Products, Exploit Code for CVE-2019-1913 Reportedly Released
blogs_tenable·2019-08-22·CVSS 9.8
[CRITICAL] Critical Cisco Vulnerabilities Across Multiple Products, Exploit Code for CVE-2019-1913 Reportedly Released
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Greynoiseio
Malicious Tag Roundup (Sep 14-30, 2021)
blogs_greynoiseio·CVSS 7.8
[HIGH] Malicious Tag Roundup (Sep 14-30, 2021)
CVE Disclosure Early Warning Get an early warning when traffic spikes indicate a high likelihood of new disclosures
Compromised Asset Detection Find out immediately if an asset communicates with a malicious IP address
Vulnerability Prioritization Get real-time insight into active exploitation trends to better understand risk and severity
SOC Efficiency Filter out noisy, low priority and false-positive alerts from mass internet scanners
Incident Investigation Add context to incidents to speed the determinations of scope and timelines
Threat Hunting Quickly identify anomalous behavior and enrich your threat hunting campaigns
Why GreyNoise
CVE Disclosure Early Warning Get an early warning when traffic spikes indicate a high likelihood of new disclosures
Compromised Asset Detection Fin
http://packetstormsecurity.com/files/154239/Cisco-UCS-IMC-Supervisor-Authentication-Bypass-Command-Injection.htmlhttp://packetstormsecurity.com/files/154305/Cisco-UCS-Director-Default-scpuser-Password.htmlhttp://seclists.org/fulldisclosure/2019/Aug/36https://seclists.org/bugtraq/2019/Aug/49https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190821-imcs-usercredhttp://packetstormsecurity.com/files/154239/Cisco-UCS-IMC-Supervisor-Authentication-Bypass-Command-Injection.htmlhttp://packetstormsecurity.com/files/154305/Cisco-UCS-Director-Default-scpuser-Password.htmlhttp://seclists.org/fulldisclosure/2019/Aug/36https://seclists.org/bugtraq/2019/Aug/49https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190821-imcs-usercred
2019-08-21
Published