A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) could allow an authenticated, remote attacker to inject arbitrary commands and obtain root privileges. The vulnerability is due to insufficient validation of user-supplied input in the Certificate Signing Request (CSR) function of the web-based management interface. An attacker could exploit this vulnerability by submitting a crafted CSR in the web-based management interface. A successful exploit could allow an attacker with administrator privileges to execute arbitrary commands on the device with full root privileges.
Metrics
Affected Vendors & Products
References
History
Wed, 20 Nov 2024 17:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
MITRE
Status: PUBLISHED
Assigner: cisco
Published: 2019-08-21T18:20:28.706884Z
Updated: 2024-11-20T17:11:47.410Z
Reserved: 2018-12-06T00:00:00
Link: CVE-2019-1896
Vulnrichment
Updated: 2024-08-04T18:35:51.570Z
NVD
Status : Analyzed
Published: 2019-08-21T19:15:15.013
Modified: 2023-03-31T15:57:37.183
Link: CVE-2019-1896
Redhat
No data.