Improper Authentication in Cisco Systems, Inc products - CVE-2019-1937
Published: August 28, 2019 / Updated: October 25, 2024
Vulnerability details
The vulnerability allows a remote attacker to bypass authentication process.
The vulnerability exists in the web-based management interface due to insufficient request header validation during the authentication process. A remote attacker can send a series of malicious requests to an affected device, use the acquired session token and gain full administrator access to the affected device.
Affected software
Cisco UCS Director Express for Big Data
Cisco UCS Director
How to mitigate CVE-2019-1937
Cisco UCS Director Express for Big Data - addressed in versions 3.7.2.0, 3.7.3.0
Cisco UCS Director - addressed in versions 6.7.2.0, 6.7.3.0
Links to Public Exploits and PoC-codes
- Exploit #10755 - Cisco UCS-IMC Supervisor 2.2.0.0 - Authentication Bypass (October 25, 2024)
- Exploit #6001 - Cisco UCS Director_ Cisco Integrated Management Controller Supervisor and Cisco UCS Director Express for Big Data - Multiple Vulnerabilities (June 17, 2021)
- Exploit #1571 - Cisco UCS Director Unauthenticated Remote Code Execution (March 18, 2020)