10
CVE-2019-1974
- EPSS 11.6%
- Veröffentlicht 21.08.2019 19:15:15
- Zuletzt bearbeitet 21.11.2024 04:37:48
- Quelle psirt@cisco.com
- Teams Watchlist Login
- Unerledigt Login
A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) Supervisor, Cisco UCS Director, and Cisco UCS Director Express for Big Data could allow an unauthenticated, remote attacker to bypass user authentication and gain access as an administrative user. The vulnerability is due to insufficient request header validation during the authentication process. An attacker could exploit this vulnerability by sending a series of malicious requests to an affected device. An exploit could allow the attacker to gain full administrative access to the affected device.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Cisco ≫ Integrated Management Controller Supervisor Version >= 2.2.0.0 <= 2.2.0.6
Cisco ≫ Integrated Management Controller Supervisor Version2.1.0.0
Cisco ≫ Ucs Director Version >= 5.5.0.0 <= 5.5.0.2
Cisco ≫ Ucs Director Version >= 6.0.0.0 <= 6.0.1.3
Cisco ≫ Ucs Director Version >= 6.5.0.0 <= 6.5.0.3
Cisco ≫ Ucs Director Version >= 6.6.0.0 <= 6.6.1.0
Cisco ≫ Ucs Director Version >= 6.7.0.0 <= 6.7.2.0
Cisco ≫ Ucs Director Version6.7(1.1)
Cisco ≫ Ucs Director Version6.7(2.0)
Cisco ≫ Ucs Director Express For Big Data Version >= 2.1.0.0 <= 2.1.0.2
Cisco ≫ Ucs Director Express For Big Data Version >= 3.0.0.0 <= 3.0.1.3
Cisco ≫ Ucs Director Express For Big Data Version >= 3.5.0.0 <= 3.5.0.3
Cisco ≫ Ucs Director Express For Big Data Version >= 3.7.0.0 <= 3.7.2.0
Cisco ≫ Ucs Director Express For Big Data Version3.6.0.0
Cisco ≫ Ucs Director Express For Big Data Version3.6.1.0
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Typ | Quelle | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 11.6% | 0.934 |
Quelle | Base Score | Exploit Score | Impact Score | Vector String |
---|---|---|---|---|
nvd@nist.gov | 9.8 | 3.9 | 5.9 |
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
nvd@nist.gov | 10 | 10 | 10 |
AV:N/AC:L/Au:N/C:C/I:C/A:C
|
psirt@cisco.com | 9.8 | 3.9 | 5.9 |
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
CWE-287 Improper Authentication
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.