CVE-2019-1908

HIGH

Cisco IMC Supervisor 2.0(13o) - Unauthenticated Sensitive Info Exposure via IPMI

Title source: llm
STIX 2.1

Description

A vulnerability in the Intelligent Platform Management Interface (IPMI) implementation of Cisco Integrated Management Controller (IMC) could allow an unauthenticated, remote attacker to view sensitive system information. The vulnerability is due to insufficient security restrictions imposed by the affected software. A successful exploit could allow the attacker to view sensitive information that belongs to other users. The attacker could then use this information to conduct additional attacks.

References (1)

Core 1
Core References

Scores

CVSS v3 7.5
EPSS 0.0200
EPSS Percentile 78.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-200
Status published
Products (2)
cisco/integrated_management_controller_supervisor 2.0.0.0 - 2.0\(13o\)
cisco/unified_computing_system 4.0\(1c\)hs3
Published Aug 21, 2019
Tracked Since Feb 18, 2026