Improper Authentication in Cisco Systems, Inc products - CVE-2019-1974
Published: August 28, 2019
Vulnerability details
The vulnerability allows a remote attacker to bypass authentication process.
The vulnerability exists in the web-based management interface due to insufficient request header validation during the authentication process. A remote attacker can send a series of malicious requests to an affected device, bypass authentication process and gain full administrative access.
Affected software
Cisco UCS Director Express for Big Data
Cisco UCS Director
How to mitigate CVE-2019-1974
Cisco UCS Director Express for Big Data - update to 3.7.3.0
Cisco UCS Director - update to 6.7.3.0