Input validation error in Cisco Systems, Inc products - CVE-2019-1936

 

Input validation error in Cisco Systems, Inc products - CVE-2019-1936

Published: August 28, 2019 / Updated: June 17, 2021


Vulnerability identifier: #VU20430
CSH Severity: Medium
CVSS v4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-1936
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: Public exploit is available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary commands on the target system.

The vulnerability exists due to insufficient validation of user-supplied input by the web-based management interface. A remote authenticated administrator can log in to the web-based management interface, send a malicious request to a certain part of the interface and execute arbitrary commands on the underlying Linux shell.


Affected software

Cisco Integrated Management Controller Supervisor
Cisco UCS Director Express for Big Data
Cisco UCS Director

How to mitigate CVE-2019-1936

Install updates from vendor's website.

Cisco Integrated Management Controller Supervisor - update to 2.2.1.0
Cisco UCS Director Express for Big Data - addressed in versions 3.7.2.0, 3.7.3.0
Cisco UCS Director - addressed in versions 6.7.2.0, 6.7.3.0

Links to Public Exploits and PoC-codes

External References

Related Security Bulletins