CVE-2019-1908
Summary
| CVE | CVE-2019-1908 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-08-21 19:15:00 UTC |
| Updated | 2020-10-16 14:52:00 UTC |
| Description | A vulnerability in the Intelligent Platform Management Interface (IPMI) implementation of Cisco Integrated Management Controller (IMC) could allow an unauthenticated, remote attacker to view sensitive system information. The vulnerability is due to insufficient security restrictions imposed by the affected software. A successful exploit could allow the attacker to view sensitive information that belongs to other users. The attacker could then use this information to conduct additional attacks. |
Risk And Classification
Problem Types: NVD-CWE-noinfo
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Cisco | Integrated Management Controller Supervisor | All | All | All | All |
| Application | Cisco | Integrated Management Controller Supervisor | All | All | All | All |
| Hardware | Cisco | Ucs C125 M5 | - | All | All | All |
| Hardware | Cisco | Ucs C125 M5 | - | All | All | All |
| Hardware | Cisco | Ucs C4200 | - | All | All | All |
| Hardware | Cisco | Ucs C4200 | - | All | All | All |
| Hardware | Cisco | Ucs S3260 | - | All | All | All |
| Hardware | Cisco | Ucs S3260 | - | All | All | All |
| Application | Cisco | Unified Computing System | 4.0(1c)hs3 | All | All | All |
| Application | Cisco | Unified Computing System | 4.0\(1c\)hs3 | All | All | All |
| Application | Cisco | Unified Computing System | 4.0\(1c\)hs3 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Cisco Integrated Management Controller Information Disclosure Vulnerability | CISCO | tools.cisco.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.