CVE-2019-1627
Last modified
CVE-2019-1627 is a medium-severity vulnerability rated 6.5/10 on the CVSS scale. A vulnerability in the Server Utilities of Cisco Integrated Management Controller (IMC) could allow an authenticated, remote attacker to gain unauthorized access to sensitive user information from the configuration data that is stored on the affected system. The vulnerability is due to insufficient protection of data in the configuration file. EPSS estimates a 1.19% chance of exploitation in the next 30 days.
Description
A vulnerability in the Server Utilities of Cisco Integrated Management Controller (IMC) could allow an authenticated, remote attacker to gain unauthorized access to sensitive user information from the configuration data that is stored on the affected system. The vulnerability is due to insufficient protection of data in the configuration file. An attacker could exploit this vulnerability by downloading the configuration file. An exploit could allow the attacker to use the sensitive information from the file to elevate privileges.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Cisco | Integrated Management Controller | All versions |
| Cisco | Unified Computing System | 4.0\(1c\)hs3 |
References
- http://www.securityfocus.com/bid/108847Third Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/108847Third Party Advisory, VDB Entry
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2019-1627?
How severe is CVE-2019-1627?
How do I fix CVE-2019-1627?
Are you affected by CVE-2019-1627?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
