Improper Authentication in Cisco Systems, Inc products - CVE-2019-1937

 

Improper Authentication in Cisco Systems, Inc products - CVE-2019-1937

Published: August 28, 2019 / Updated: October 25, 2024


Vulnerability identifier: #VU20429
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-1937
CWE-ID: CWE-287
Exploitation vector: Remote access
Exploit availability: Public exploit is available

Vulnerability details

The vulnerability allows a remote attacker to bypass authentication process.

The vulnerability exists in the web-based management interface due to insufficient request header validation during the authentication process. A remote attacker can send a series of malicious requests to an affected device, use the acquired session token and gain full administrator access to the affected device.


Affected software

Cisco Integrated Management Controller Supervisor
Cisco UCS Director Express for Big Data
Cisco UCS Director

How to mitigate CVE-2019-1937

Install updates from vendor's website.

Cisco Integrated Management Controller Supervisor - update to 2.2.1.0
Cisco UCS Director Express for Big Data - addressed in versions 3.7.2.0, 3.7.3.0
Cisco UCS Director - addressed in versions 6.7.2.0, 6.7.3.0

Links to Public Exploits and PoC-codes

External References

Related Security Bulletins