Description
A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) could allow an authenticated, remote attacker to inject arbitrary commands and obtain root privileges. The vulnerability is due to insufficient validation of user-supplied input in the Certificate Signing Request (CSR) function of the web-based management interface. An attacker could exploit this vulnerability by submitting a crafted CSR in the web-based management interface. A successful exploit could allow an attacker with administrator privileges to execute arbitrary commands on the device with full root privileges.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2019-10453 | A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) could allow an authenticated, remote attacker to inject arbitrary commands and obtain root privileges. The vulnerability is due to insufficient validation of user-supplied input in the Certificate Signing Request (CSR) function of the web-based management interface. An attacker could exploit this vulnerability by submitting a crafted CSR in the web-based management interface. A successful exploit could allow an attacker with administrator privileges to execute arbitrary commands on the device with full root privileges. |
References
History
Wed, 20 Nov 2024 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Subscriptions
Cisco
Subscribe
Encs 5100
Subscribe
Encs 5400
Subscribe
Integrated Management Controller Supervisor
Subscribe
Ucs-e1120d-m3
Subscribe
Ucs-e140s-m2
Subscribe
Ucs-e160d-m2
Subscribe
Ucs-e160s-m3
Subscribe
Ucs-e168d-m2
Subscribe
Ucs-e180d-m3
Subscribe
Ucs C125 M5
Subscribe
Ucs C4200
Subscribe
Ucs S3260
Subscribe
Unified Computing System
Subscribe
Status: PUBLISHED
Assigner: cisco
Published:
Updated: 2024-11-20T17:11:47.410Z
Reserved: 2018-12-06T00:00:00.000Z
Link: CVE-2019-1896
Updated: 2024-08-04T18:35:51.570Z
Status : Modified
Published: 2019-08-21T19:15:15.013
Modified: 2024-11-21T04:37:38.333
Link: CVE-2019-1896
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD