CVE-2019-1863
Summary
| CVE | CVE-2019-1863 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-08-21 19:15:00 UTC |
| Updated | 2020-10-16 14:51:00 UTC |
| Description | A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) Software could allow an authenticated, remote attacker to make unauthorized changes to the system configuration. The vulnerability is due to insufficient authorization enforcement. An attacker could exploit this vulnerability by sending a crafted HTTP request to the affected software. A successful exploit could allow a user with read-only privileges to change critical system configurations using administrator privileges. |
Risk And Classification
Problem Types: NVD-CWE-Other
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Cisco | Encs 5100 | - | All | All | All |
| Hardware | Cisco | Encs 5100 | - | All | All | All |
| Hardware | Cisco | Encs 5400 | - | All | All | All |
| Hardware | Cisco | Encs 5400 | - | All | All | All |
| Application | Cisco | Integrated Management Controller Supervisor | All | All | All | All |
| Application | Cisco | Integrated Management Controller Supervisor | All | All | All | All |
| Hardware | Cisco | Ucs-e1120d-m3 | - | All | All | All |
| Hardware | Cisco | Ucs-e1120d-m3 | - | All | All | All |
| Hardware | Cisco | Ucs-e140s-m2 | - | All | All | All |
| Hardware | Cisco | Ucs-e140s-m2 | - | All | All | All |
| Hardware | Cisco | Ucs-e160d-m2 | - | All | All | All |
| Hardware | Cisco | Ucs-e160d-m2 | - | All | All | All |
| Hardware | Cisco | Ucs-e160s-m3 | - | All | All | All |
| Hardware | Cisco | Ucs-e160s-m3 | - | All | All | All |
| Hardware | Cisco | Ucs-e168d-m2 | - | All | All | All |
| Hardware | Cisco | Ucs-e168d-m2 | - | All | All | All |
| Hardware | Cisco | Ucs-e180d-m3 | - | All | All | All |
| Hardware | Cisco | Ucs-e180d-m3 | - | All | All | All |
| Hardware | Cisco | Ucs C125 M5 | - | All | All | All |
| Hardware | Cisco | Ucs C125 M5 | - | All | All | All |
| Hardware | Cisco | Ucs C4200 | - | All | All | All |
| Hardware | Cisco | Ucs C4200 | - | All | All | All |
| Hardware | Cisco | Ucs S3260 | - | All | All | All |
| Hardware | Cisco | Ucs S3260 | - | All | All | All |
| Application | Cisco | Unified Computing System | 4.0(1c)hs3 | All | All | All |
| Application | Cisco | Unified Computing System | 4.0\(1c\)hs3 | All | All | All |
| Application | Cisco | Unified Computing System | 4.0\(1c\)hs3 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Cisco Integrated Management Controller Privilege Escalation Vulnerability | CISCO | tools.cisco.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.