#VU20430 Input validation error in Cisco Systems, Inc products - CVE-2019-1936
Published: August 28, 2019 / Updated: June 17, 2021
Cisco UCS Director Express for Big Data
Cisco UCS Director
Cisco Integrated Management Controller Supervisor
Cisco Systems, Inc
Description
The vulnerability allows a remote attacker to execute arbitrary commands on the target system.
The vulnerability exists due to insufficient validation of user-supplied input by the web-based management interface. A remote authenticated administrator can log in to the web-based management interface, send a malicious request to a certain part of the interface and execute arbitrary commands on the underlying Linux shell.