CVE-2019-1937 is a critical authentication bypass vulnerability affecting the web-based management interfaces of Cisco Integrated Management Controller (IMC) Supervisor, Cisco UCS Director, and Cisco UCS Director Express for Big Data. This flaw allows an unauthenticated, remote attacker to acquire a valid administrator session token due to insufficient request header validation. With a CVSS score of 9.8 (CRITICAL), the vulnerability is easily exploitable over the network with low attack complexity, leading to full administrator access and complete system compromise. While not listed in CISA's KEV catalog, public exploit code exists, including a Metasploit module and an ExploitDB entry, indicating a high potential for exploitation. The CVE has garnered significant community attention and media coverage, underscoring its severity and the need for immediate patching.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 2.2.0.3, <= 2.2.0.6CPE matchmatch criteria | cpe:2.3:a:cisco:integrated_management_controller_supervisor:*:*:*:*:*:*:*:* | ||
>= 6.6.0.0, <= 6.6.1.0CPE matchmatch criteria | cpe:2.3:a:cisco:ucs_director:*:*:*:*:*:*:*:* | ||
>= 6.7.0.0, <= 6.7.1.0CPE matchmatch criteria | cpe:2.3:a:cisco:ucs_director:*:*:*:*:*:*:*:* | ||
6.7\(0.0.67265\)CPE matchmatch criteria | cpe:2.3:a:cisco:ucs_director:6.7\(0.0.67265\):*:*:*:*:*:*:* | ||
>= 3.7.0.0, <= 3.7.1.0CPE matchmatch criteria | cpe:2.3:a:cisco:ucs_director_express_for_big_data:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.