CVE-2019-1907
Last modified
CVE-2019-1907 is a high-severity vulnerability rated 8.8/10 on the CVSS scale. A vulnerability in the web server of Cisco Integrated Management Controller (IMC) could allow an authenticated, remote attacker to set sensitive configuration values and gain elevated privileges. The vulnerability is due to improper handling of substring comparison operations that are performed by the affected software. EPSS estimates a 1.37% chance of exploitation in the next 30 days.
Description
A vulnerability in the web server of Cisco Integrated Management Controller (IMC) could allow an authenticated, remote attacker to set sensitive configuration values and gain elevated privileges. The vulnerability is due to improper handling of substring comparison operations that are performed by the affected software. An attacker could exploit this vulnerability by sending a crafted HTTP request to the affected software. A successful exploit could allow the attacker with read-only privileges to gain administrator privileges.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Cisco | Unified Computing System | 4.0\(1c\)hs3 |
| Cisco | Integrated Management Controller Supervisor | < 4.0\(4b\) |
| Cisco | Integrated Management Controller Supervisor | < 4.0\(2f\) |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2019-1907?
How severe is CVE-2019-1907?
How do I fix CVE-2019-1907?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2019
- CVE-2019-19064A memory leak in the fsl_lpspi_probe() function in drivers/s…7.5
- CVE-2019-19065A memory leak in the sdma_init() function in drivers/infinib…4.7
- CVE-2019-19066A memory leak in the bfad_im_get_stats() function in drivers…4.7
- CVE-2019-19067Four memory leaks in the acp_hw_init() function in drivers/g…4.4
- CVE-2019-19068A memory leak in the rtl8xxxu_submit_int_urb() function in d…4.6
- CVE-2019-19069A memory leak in the fastrpc_dma_buf_attach() function in dr…7.5
- CVE-2019-19070A memory leak in the spi_gpio_probe() function in drivers/sp…7.5
- CVE-2019-19071A memory leak in the rsi_send_beacon() function in drivers/n…7.5
- CVE-2019-19072A memory leak in the predicate_parse() function in kernel/tr…4.4
- CVE-2019-19073Memory leaks in drivers/net/wireless/ath/ath9k/htc_hst.c in …4
- CVE-2019-19074A memory leak in the ath9k_wmi_cmd() function in drivers/net…7.5
- CVE-2019-19075A memory leak in the ca8210_probe() function in drivers/net/…7.5
Are you affected by CVE-2019-1907?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
