cbcvebase.
CVE-2019-1974
published 2019-08-21

CVE-2019-1974: A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) Supervisor, Cisco UCS Director, and Cisco UCS Director…

PriorityP271critical9.8CVSS 3.0
AVNACLPRNUINSUCHIHAH
EPSS
4.49%
90.4th percentile
A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) Supervisor, Cisco UCS Director, and Cisco UCS Director Express for Big Data could allow an unauthenticated, remote attacker to bypass user authentication and gain access as an administrative user. The vulnerability is due to insufficient request header validation during the authentication process. An attacker could exploit this vulnerability by sending a series of malicious requests to an affected device. An exploit could allow the attacker to gain full administrative access to the affected device.

Affected

17 ranges
VendorProductVersion rangeFixed in
ciscocisco_unified_computing_system_director>= unspecified < 6.7.3.06.7.3.0
ciscoimc_supervisor_cisco_ucs_director_and_cisco_ucs_director_express_for_big_data
ciscointegrated_management_controller_supervisor
ciscointegrated_management_controller_supervisor2.2.0.0 – 2.2.0.6
ciscoucs_director
ciscoucs_director
ciscoucs_director5.5.0.0 – 5.5.0.2
ciscoucs_director6.0.0.0 – 6.0.1.3
ciscoucs_director6.5.0.0 – 6.5.0.3
ciscoucs_director6.6.0.0 – 6.6.1.0
ciscoucs_director6.7.0.0 – 6.7.2.0
ciscoucs_director_express_for_big_data
ciscoucs_director_express_for_big_data
ciscoucs_director_express_for_big_data2.1.0.0 – 2.1.0.2
ciscoucs_director_express_for_big_data3.0.0.0 – 3.0.1.3
ciscoucs_director_express_for_big_data3.5.0.0 – 3.5.0.3
ciscoucs_director_express_for_big_data3.7.0.0 – 3.7.2.0

Detection & IOCsextracted from sources · hover to see the quote

  • The vulnerability is triggered by sending malicious HTTP requests with manipulated/insufficient request headers during the authentication process to the web-based management interface. Detection should focus on anomalous or unexpected HTTP request headers in authentication flows targeting Cisco IMC Supervisor, UCS Director, or UCS Director Express for Big Data management interfaces.
  • Monitor for unauthenticated sessions gaining administrative access to the web-based management interface of Cisco IMC Supervisor, Cisco UCS Director, or Cisco UCS Director Express for Big Data — a successful exploit grants full administrative access without valid credentials.
  • ·No workarounds are available for this vulnerability; patching is the only remediation. Ensure affected products (Cisco IMC Supervisor, Cisco UCS Director, Cisco UCS Director Express for Big Data) are updated to versions that address this advisory.

CVSS provenance

nvdv3.09.8CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
vendor_cisco9.8CRITICAL
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.