CVE-2019-1936
published 2019-08-21CVE-2019-1936: A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) Supervisor, Cisco UCS Director, and Cisco UCS Director…
PriorityP266high7.2CVSS 3.1
AVNACLPRHUINSUCHIHAH
EXPLOIT
EPSS
39.48%
98.5th percentile
A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) Supervisor, Cisco UCS Director, and Cisco UCS Director Express for Big Data could allow an authenticated, remote attacker to execute arbitrary commands on the underlying Linux shell as the root user. Exploitation of this vulnerability requires privileged access to an affected device. The vulnerability is due to insufficient validation of user-supplied input by the web-based management interface. An attacker could exploit this vulnerability by logging in to the web-based management interface with administrator privileges and then sending a malicious request to a certain part of the interface.
Affected
16 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | cisco_unified_computing_system_director | >= unspecified < 6.7.3.0 | 6.7.3.0 |
| cisco | integrated_management_controller_supervisor | — | — |
| cisco | integrated_management_controller_supervisor | 2.2.0.0 – 2.2.0.6 | — |
| cisco | integrated_management_controller_supervisor_cisco_ucs_director_and_cisco_ucs_dir | — | — |
| cisco | ucs_director | — | — |
| cisco | ucs_director | — | — |
| cisco | ucs_director | — | — |
| cisco | ucs_director | — | — |
| cisco | ucs_director | — | — |
| cisco | ucs_director | — | — |
| cisco | ucs_director | — | — |
| cisco | ucs_director_express_for_big_data | — | — |
| cisco | ucs_director_express_for_big_data | — | — |
| cisco | ucs_director_express_for_big_data | — | — |
| cisco | ucs_director_express_for_big_data | — | — |
| cisco | ucs_director_express_for_big_data | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Detect authentication bypass (CVE-2019-1937, chained with CVE-2019-1936) by monitoring HTTP requests to /app/ui/ClientServlet that simultaneously carry both X-Starship-UserSession-Key and X-Starship-Request-Key headers alongside a JSESSIONID cookie — this header combination is the bypass trigger. ↗
- →Alert on HTTP responses from /app/ui/ClientServlet that return a JSON body containing '"loginName":"admin"' following a request that did not go through a normal login flow — this indicates a successful authentication bypass. ↗
- →Monitor for command injection exploitation via the password change form in the web-based management interface, executed as root on the underlying Linux shell. ↗
- →Flag use of the Metasploit module targeting Cisco UCS Director RCE (linux/http/cisco_ucs_rce) against UCS Director versions 6.6.0 and 6.7.0. ↗
- →Detect SSH login attempts using a known default unprivileged user credential on the Cisco UCS Director virtual appliance. ↗
- →Inspect the AuthenticationFilter class (com.cloupia.client.web.auth.AuthenticationFilter) for the isStarshipRequest() code path that creates an unauthenticated admin session — presence of this logic in deployed JARs indicates a vulnerable version. ↗
- ·The authentication bypass (CVE-2019-1937) is a prerequisite chained with CVE-2019-1936 in the Metasploit module; the command injection alone requires authenticated administrator access per Cisco's advisory. ↗
- ·The Metasploit module was only tested against Cisco UCS Director 6.6.0 and 6.7.0; IMC Supervisor and UCS Director Express for Big Data are listed as affected by Cisco but were not independently verified by the researcher. ↗
- ·In some exploitation scenarios the server authenticates the original JSESSIONID cookie rather than issuing a new one, but the result is equivalent — the existing cookie gains admin privileges. ↗
CVSS provenance
nvdv3.17.2HIGHCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
nvdv3.07.2HIGHCVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
nvdv2.09.0CRITICALAV:N/AC:L/Au:S/C:C/I:C/A:C
vendor_cisco7.2HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco Integrated Management Controller Supervisor, Cisco UCS Director, and Cisco UCS Director Express for Big Data Command Injection Vulnerability
vendor_cisco·2019-08-21·CVSS 7.2
CVE-2019-1936 [HIGH] CWE-20 Cisco Integrated Management Controller Supervisor, Cisco UCS Director, and Cisco UCS Director Express for Big Data Command Injection Vulnerability
Cisco Integrated Management Controller Supervisor, Cisco UCS Director, and Cisco UCS Director Express for Big Data Command Injection Vulnerability
A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) Supervisor, Cisco UCS Director, and Cisco UCS Director Express for Big Data could allow an authenticated, remote attacker to execute arbitrary commands on the underlying Linux shell as the root user. Exploitation of this vulnerability requires privileged access to an affected device.
The vulnerability is due to insufficient validation of user-supplied input by the web-based management interface. An attacker could exploit this vulnerability by logging in to the web-based management interface with administrator privileges and then sending a malic
Cisco
Cisco Integrated Management Controller Supervisor, Cisco UCS Director, and Cisco UCS Director Express for Big Data Command Injection Vulnerability
vendor_cisco·CVSS 3.0
CVE-2019-1936 Cisco Integrated Management Controller Supervisor, Cisco UCS Director, and Cisco UCS Director Express for Big Data Command Injection Vulnerability
CVE-2019-1936: Cisco Integrated Management Controller Supervisor, Cisco UCS Director, and Cisco UCS Director Express for Big Data Command Injection Vulnerability
A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) Supervisor, Cisco UCS Director, and Cisco UCS Director Express for Big Data could allow an authenticated, remote attacker to execute arbitrary commands on the underlying Linux shell as the root user. Exploitation of this vulnerability requires privileged access to an affected device. The vulnerability is due to insufficient validation of user-supplied input by the web-based management interface. An attacker could exploit this vulnerability by logging in to the web-based management interface with administrator privileges and then s
GHSA
GHSA-v93p-j269-v6hr: A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) Supervisor, Cisco UCS Director, and Cisco UCS Di
ghsa_unreviewed·2022-05-24
CVE-2019-1936 [HIGH] CWE-20 GHSA-v93p-j269-v6hr: A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) Supervisor, Cisco UCS Director, and Cisco UCS Di
A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) Supervisor, Cisco UCS Director, and Cisco UCS Director Express for Big Data could allow an authenticated, remote attacker to execute arbitrary commands on the underlying Linux shell as the root user. Exploitation of this vulnerability requires privileged access to an affected device. The vulnerability is due to insufficient validation of user-supplied input by the web-based management interface. An attacker could exploit this vulnerability by logging in to the web-based management interface with administrator privileges and then sending a malicious request to a certain part of the interface.
No detection rules found.
Exploit-DB
Cisco UCS Director_ Cisco Integrated Management Controller Supervisor and Cisco UCS Director Express for Big Data - Multiple Vulnerabilities
exploitdb·2019-08-21
Cisco UCS Director_ Cisco Integrated Management Controller Supervisor and Cisco UCS Director Express for Big Data - Multiple Vulnerabilities
Cisco UCS Director_ Cisco Integrated Management Controller Supervisor and Cisco UCS Director Express for Big Data - Multiple Vulnerabilities
---
>> Multiple critical vulnerabilities in Cisco UCS Director, Cisco Integrated Management Controller Supervisor and Cisco UCS Director Express for Big Data
>> Discovered by Pedro Ribeiro ([email protected]) from Agile Information Security
Disclosure: 21/08/2019 / Last updated: 22/08/2019
>> Executive summary:
Cisco UCS Director (UCS) is a cloud orchestration product that automates common private cloud infrastructure management functions. It is built using Java and a variety of other technologies and distributed as a Linux based virtual appliance. A demo of the UCS virtual appliance can be freely downloaded from Cisco's website [1].
Due to severa
Metasploit
Cisco UCS Director Unauthenticated Remote Code Execution
metasploit·CVSS 7.2
CVE-2019-1937 [HIGH] Cisco UCS Director Unauthenticated Remote Code Execution
Cisco UCS Director Unauthenticated Remote Code Execution
The Cisco UCS Director virtual appliance contains two flaws that can be combined and abused by an attacker to achieve remote code execution as root. The first one, CVE-2019-1937, is an authentication bypass, that allows the attacker to authenticate as an administrator. The second one, CVE-2019-1936, is a command injection in a password change form, that allows the attacker to inject commands that will execute as root. This module combines both vulnerabilities to achieve the unauthenticated command injection as root. It has been tested with Cisco UCS Director virtual machines 6.6.0 and 6.7.0. Note that Cisco also mentions in their advisory that their IMC Supervisor and UCS Director Express are also affected by these vulnerabilities,
http://packetstormsecurity.com/files/154239/Cisco-UCS-IMC-Supervisor-Authentication-Bypass-Command-Injection.htmlhttp://packetstormsecurity.com/files/154308/Cisco-UCS-Director-Unauthenticated-Remote-Code-Execution.htmlhttp://seclists.org/fulldisclosure/2019/Aug/36https://seclists.org/bugtraq/2019/Aug/49https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190821-imcs-ucs-cmdinjhttp://packetstormsecurity.com/files/154239/Cisco-UCS-IMC-Supervisor-Authentication-Bypass-Command-Injection.htmlhttp://packetstormsecurity.com/files/154308/Cisco-UCS-Director-Unauthenticated-Remote-Code-Execution.htmlhttp://seclists.org/fulldisclosure/2019/Aug/36https://seclists.org/bugtraq/2019/Aug/49https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190821-imcs-ucs-cmdinj
2019-08-21
Published