Improper Authentication in Cisco Systems, Inc products - CVE-2019-1974

 

Improper Authentication in Cisco Systems, Inc products - CVE-2019-1974

Published: August 28, 2019


Vulnerability identifier: #VU20427
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-1974
CWE-ID: CWE-287
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to bypass authentication process.

The vulnerability exists in the web-based management interface due to insufficient request header validation during the authentication process. A remote attacker can send a series of malicious requests to an affected device, bypass authentication process and gain full administrative access.


Affected software

Cisco Integrated Management Controller Supervisor
Cisco UCS Director Express for Big Data
Cisco UCS Director

How to mitigate CVE-2019-1974

Install updates from vendor's website.

Cisco Integrated Management Controller Supervisor - update to 2.2.1.0
Cisco UCS Director Express for Big Data - update to 3.7.3.0
Cisco UCS Director - update to 6.7.3.0

External References

Related Security Bulletins