Input validation error in Cisco Systems, Inc products - CVE-2019-1936
Published: August 28, 2019 / Updated: June 17, 2021
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary commands on the target system.
The vulnerability exists due to insufficient validation of user-supplied input by the web-based management interface. A remote authenticated administrator can log in to the web-based management interface, send a malicious request to a certain part of the interface and execute arbitrary commands on the underlying Linux shell.
Affected software
Cisco UCS Director Express for Big Data
Cisco UCS Director
How to mitigate CVE-2019-1936
Cisco UCS Director Express for Big Data - addressed in versions 3.7.2.0, 3.7.3.0
Cisco UCS Director - addressed in versions 6.7.2.0, 6.7.3.0