CVE-2019-1936 is a critical command injection vulnerability in the web-based management interfaces of Cisco Integrated Management Controller (IMC) Supervisor, Cisco UCS Director, and Cisco UCS Director Express for Big Data. It allows an authenticated, remote attacker with administrator privileges to execute arbitrary commands as root on the underlying Linux shell due to insufficient input validation. With a CVSS score of 7.2 (High) and a FAUCET Risk Score of 98/100, this vulnerability poses a significant risk, enabling full compromise of affected systems. While not listed in KEV, a Metasploit module exists, and it has garnered some community discussion and media coverage, indicating its exploitability and potential impact.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 2.2.0.0, <= 2.2.0.6CPE matchmatch criteria | cpe:2.3:a:cisco:integrated_management_controller_supervisor:*:*:*:*:*:*:*:* | ||
2.1.0.0CPE matchmatch criteria | cpe:2.3:a:cisco:integrated_management_controller_supervisor:2.1.0.0:*:*:*:*:*:*:* | ||
6.0.0.0CPE matchmatch criteria | cpe:2.3:a:cisco:ucs_director:6.0.0.0:*:*:*:*:*:*:* | ||
6.5.0.0CPE matchmatch criteria | cpe:2.3:a:cisco:ucs_director:6.5.0.0:*:*:*:*:*:*:* | ||
6.6.0.0CPE matchmatch criteria | cpe:2.3:a:cisco:ucs_director:6.6.0.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.3 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.