CVE-2019-1908
Last modified
CVE-2019-1908 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. A vulnerability in the Intelligent Platform Management Interface (IPMI) implementation of Cisco Integrated Management Controller (IMC) could allow an unauthenticated, remote attacker to view sensitive system information. The vulnerability is due to insufficient security restrictions imposed by the affected software. EPSS estimates a 2.00% chance of exploitation in the next 30 days.
Description
A vulnerability in the Intelligent Platform Management Interface (IPMI) implementation of Cisco Integrated Management Controller (IMC) could allow an unauthenticated, remote attacker to view sensitive system information. The vulnerability is due to insufficient security restrictions imposed by the affected software. A successful exploit could allow the attacker to view sensitive information that belongs to other users. The attacker could then use this information to conduct additional attacks.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Cisco | Unified Computing System | 4.0\(1c\)hs3 |
| Cisco | Integrated Management Controller Supervisor | >= 2.0.0.0, < 2.0\(13o\) |
| Cisco | Integrated Management Controller Supervisor | >= 3.0.0.0, < 3.0\(4k\) |
| Cisco | Integrated Management Controller Supervisor | >= 4.0.0.0, < 4.0\(4b\) |
| Cisco | Integrated Management Controller Supervisor | >= 4.0.0.0, < 4.0\(2f\) |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2019-1908?
How severe is CVE-2019-1908?
How do I fix CVE-2019-1908?
Are you affected by CVE-2019-1908?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
