Your RSA-2048 keys break in 2030. Find every one of them before attackers do.

CVE-2019-1937

CRITICAL

A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) Supervisor, Cisco UCS Director, and Cisco UCS Director Express for Big Data could…

Published
Aug 21, 2019
Updated
Nov 21, 2024
Affected
0 pkgs
Patched
None yet
Exploits
3 known

EPSS Exploitation Probability

via FIRST.org ↗
90.4%probability of exploitation in next 30 days
Very High Risk100th percentile-0.05%
89.9%90.4%90.9%91.4%90.9%90.4%Dec 25Apr 26Jun 26

EPSS (Exploit Prediction Scoring System) is a daily probability model maintained by FIRST.org. It estimates the likelihood a CVE will be exploited in production environments within the next 30 days, derived from real-world threat intelligence signals.

Description

A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) Supervisor, Cisco UCS Director, and Cisco UCS Director Express for Big Data could allow an unauthenticated, remote attacker to acquire a valid session token with administrator privileges, bypassing user authentication. The vulnerability is due to insufficient request header validation during the authentication process. An attacker could exploit this vulnerability by sending a series of malicious requests to an affected device. An exploit could allow the attacker to use the acquired session token to gain full administrator access to the affected device.

Affected Products

3 products · 6 configurations
Application
integrated management controller supervisorcisco
≥ 2.2.0.3 && ≤ 2.2.0.6
range
Application
ucs directorcisco
≥ 6.7.0.0 && ≤ 6.7.1.0
1 version
6.7\(0.0.67265\)
Application
ucs director express for big datacisco
≥ 3.7.0.0 && ≤ 3.7.1.0
1 version
3.6.0.0
Exploits & PoCs
3

Research use only. For defensive security, authorized penetration testing, and academic research only. Never execute exploit code against systems without explicit written authorization.

EDB-51589webappshardware

Cisco UCS-IMC Supervisor 2.2.0.0 - Authentication Bypass

by Fatih Sencer · Jul 15, 2023

Frequently Asked Questions

A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) Supervisor, Cisco UCS Director, and Cisco UCS Director Express for Big Data could allow an unauthenticated, remote attacker to acquire a valid session token with administrator privileges, bypassing user authentication. The vulnerability is due to insufficient request header validation during the authentication process. An attacker could exploit this vulnerability by sending a series of malicious requests to an affected device. An exploit could allow the attacker to use the acquired session tok
O3 Security · Impact-Aware SCA

Is CVE-2019-1937 in your stack?

O3 detects CVE-2019-1937 across dependencies and uses function-level reachability to confirm whether the vulnerable code path is actually reachable — not just present. No false positives.