CVE-2019-1896 is a high-severity command injection vulnerability affecting the web-based management interface of Cisco Integrated Management Controller (IMC). An authenticated, remote attacker with administrator privileges can exploit insufficient input validation in the Certificate Signing Request (CSR) function by submitting a crafted CSR. This allows for arbitrary command execution with root privileges, leading to complete compromise of the device. While no public exploit code or active exploitation is reported, the vulnerability has garnered some community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
4.0\(1c\)hs3CPE matchmatch criteria | cpe:2.3:a:cisco:unified_computing_system:4.0\(1c\)hs3:*:*:*:*:*:*:* | ||
>= 2.0.0.0, < 2.0\(13o\)CPE matchmatch criteria | cpe:2.3:a:cisco:integrated_management_controller_supervisor:*:*:*:*:*:*:*:* | ||
>= 3.0.0.0, < 3.0\(4k\)CPE matchmatch criteria | cpe:2.3:a:cisco:integrated_management_controller_supervisor:*:*:*:*:*:*:*:* | ||
>= 4.0.0.0, < 4.0\(4b\)CPE matchmatch criteria | cpe:2.3:a:cisco:integrated_management_controller_supervisor:*:*:*:*:*:*:*:* | ||
>= 4.0.0.0, < 4.0\(2f\)CPE matchmatch criteria | cpe:2.3:a:cisco:integrated_management_controller_supervisor:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.3 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.