Vulnerability Description
A vulnerability in the Import Cisco IMC configuration utility of Cisco Integrated Management Controller (IMC) could allow an authenticated, remote attacker to cause a denial of service (DoS) condition and implement arbitrary commands with root privileges on an affected device. The vulnerability is due to improper bounds checking by the import-config process. An attacker could exploit this vulnerability by sending malicious packets to an affected device. When the packets are processed, an exploitable buffer overflow condition may occur. A successful exploit could allow the attacker to implement arbitrary code on the affected device with elevated privileges.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Cisco | Unified Computing System | 4.0\(1c\)hs3 |
| Cisco | Integrated Management Controller Supervisor | >= 3.0.0.0, < 3.0\(4k\) |
| Cisco | Encs 5100 | - |
| Cisco | Encs 5400 | - |
| Cisco | Ucs-E1120D-M3 | - |
| Cisco | Ucs-E140S-M2 | - |
| Cisco | Ucs-E160D-M2 | - |
| Cisco | Ucs-E160S-M3 | - |
| Cisco | Ucs-E168D-M2 | - |
| Cisco | Ucs-E180D-M3 | - |
| Cisco | Ucs C125 M5 | - |
| Cisco | Ucs C4200 | - |
| Cisco | Ucs S3260 | - |
Related Weaknesses (CWE)
References
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-2Vendor Advisory
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-2Vendor Advisory
FAQ
What is CVE-2019-1871?
CVE-2019-1871 is a vulnerability with a CVSS score of 7.2 (HIGH). A vulnerability in the Import Cisco IMC configuration utility of Cisco Integrated Management Controller (IMC) could allow an authenticated, remote attacker to cause a denial of service (DoS) condition...
How severe is CVE-2019-1871?
CVE-2019-1871 has been rated HIGH with a CVSS base score of 7.2/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-1871?
Check the references section above for vendor advisories and patch information. Affected products include: Cisco Unified Computing System, Cisco Integrated Management Controller Supervisor, Cisco Encs 5100, Cisco Encs 5400, Cisco Ucs-E1120D-M3.