CVE-2019-1871

HIGH

Cisco IMC Supervisor 3.0.0.0-3.0(4k) - Authenticated DoS & RCE via Import Utility

Title source: llm
STIX 2.1

Description

A vulnerability in the Import Cisco IMC configuration utility of Cisco Integrated Management Controller (IMC) could allow an authenticated, remote attacker to cause a denial of service (DoS) condition and implement arbitrary commands with root privileges on an affected device. The vulnerability is due to improper bounds checking by the import-config process. An attacker could exploit this vulnerability by sending malicious packets to an affected device. When the packets are processed, an exploitable buffer overflow condition may occur. A successful exploit could allow the attacker to implement arbitrary code on the affected device with elevated privileges.

References (1)

Core 1
Core References

Scores

CVSS v3 7.2
EPSS 0.0329
EPSS Percentile 86.9%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-119
Status published
Products (2)
cisco/integrated_management_controller_supervisor 3.0.0.0 - 3.0\(4k\)
cisco/unified_computing_system 4.0\(1c\)hs3
Published Aug 21, 2019
Tracked Since Feb 18, 2026