CVE-2019-1935 is a critical vulnerability affecting Cisco Integrated Management Controller (IMC) Supervisor, Cisco UCS Director, and Cisco UCS Director Express for Big Data. It allows an unauthenticated, remote attacker to log in to the CLI using a documented default "scpuser" account with an undocumented default password and incorrect permissions. This vulnerability carries a CVSS score of 9.8 (CRITICAL) due to its network-based attack vector, low complexity, and complete compromise potential, including full read/write access to the system's database. While not listed in CISA's KEV catalog, public exploit code, including a Metasploit module, is available, and it has garnered significant community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 2.2.0.0, <= 2.2.0.6CPE matchmatch criteria | cpe:2.3:a:cisco:integrated_management_controller_supervisor:*:*:*:*:*:*:*:* | ||
2.1.0.0CPE matchmatch criteria | cpe:2.3:a:cisco:integrated_management_controller_supervisor:2.1.0.0:*:*:*:*:*:*:* | ||
6.0.0.0CPE matchmatch criteria | cpe:2.3:a:cisco:ucs_director:6.0.0.0:*:*:*:*:*:*:* | ||
6.5.0.0CPE matchmatch criteria | cpe:2.3:a:cisco:ucs_director:6.5.0.0:*:*:*:*:*:*:* | ||
6.6.0.0CPE matchmatch criteria | cpe:2.3:a:cisco:ucs_director:6.6.0.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.