CVE-2019-1966 is a privilege escalation vulnerability in Cisco UCS Fabric Interconnect Software, specifically within the local management CLI. An authenticated, local attacker can exploit extraneous subcommand options to execute arbitrary operating system commands as root. This vulnerability has a CVSS score of 7.8 (High), indicating a significant impact with high confidentiality, integrity, and availability compromise. While no public exploit code (Metasploit, Nuclei, ExploitDB) is available, the vulnerability has received some community discussion and media coverage, including an article from BleepingComputer. It is not currently listed on CISA's KEV catalog, suggesting no active exploitation is publicly known.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 3.2CPE matchmatch criteria | cpe:2.3:o:cisco:nx-os:*:*:*:*:*:*:*:* | ||
4.0CPE matchmatch criteria | cpe:2.3:o:cisco:nx-os:4.0:*:*:*:*:*:*:* | ||
3.2\(3b\)aCPE matchmatch criteria | cpe:2.3:a:cisco:unified_computing_system:3.2\(3b\)a:*:*:*:*:*:*:* | ||
4.0\(1a\)aCPE matchmatch criteria | cpe:2.3:a:cisco:unified_computing_system:4.0\(1a\)a:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.