CVE-2019-1896

HIGH

Cisco Integrated Management Controller Supervisor 2.0.0.0-2.0(13o) - Authenticated OS Command Injection via CSR Function

Title source: llm
STIX 2.1

Description

A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) could allow an authenticated, remote attacker to inject arbitrary commands and obtain root privileges. The vulnerability is due to insufficient validation of user-supplied input in the Certificate Signing Request (CSR) function of the web-based management interface. An attacker could exploit this vulnerability by submitting a crafted CSR in the web-based management interface. A successful exploit could allow an attacker with administrator privileges to execute arbitrary commands on the device with full root privileges.

References (1)

Core 1

Scores

CVSS v3 7.2
EPSS 0.0182
EPSS Percentile 76.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-78
Status published
Products (2)
cisco/integrated_management_controller_supervisor 2.0.0.0 - 2.0\(13o\)
cisco/unified_computing_system 4.0\(1c\)hs3
Published Aug 21, 2019
Tracked Since Feb 18, 2026