Use of hard-coded credentials in Cisco Systems, Inc products - CVE-2019-1935

 

Use of hard-coded credentials in Cisco Systems, Inc products - CVE-2019-1935

Published: August 28, 2019 / Updated: June 17, 2021


Vulnerability identifier: #VU20431
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-1935
CWE-ID: CWE-798
Exploitation vector: Remote access
Exploit availability: Public exploit is available

Vulnerability details

The vulnerability allows a remote attacker to gain full access to vulnerable system.

The vulnerability exists due to the presence of a documented default account with an undocumented default password and incorrect permission settings for that account. A remote unauthenticated attacker can log in to the CLI of an affected system by using the SCP User account (scpuser) with default user credentials and execute arbitrary commands on the target system. This includes full read and write access to the system's database.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.

Affected software

Cisco Integrated Management Controller Supervisor
Cisco UCS Director Express for Big Data
Cisco UCS Director

How to mitigate CVE-2019-1935

Install updates from vendor's website.

Cisco Integrated Management Controller Supervisor - update to 2.2.1.0
Cisco UCS Director Express for Big Data - addressed in versions 3.7.2.0, 3.7.3.0
Cisco UCS Director - addressed in versions 6.7.2.0, 6.7.3.0

Links to Public Exploits and PoC-codes

External References

Related Security Bulletins