Back

CVE-2019-1937

CRITICAL

A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) Supervisor, Cisco UCS Director, and Cisco UCS Director Express for Big Data could allow an unauthenticated, remote attacker to acquire a valid session token with administrator privileges, bypassing user authentication. The vulnerability is due to insufficient request header validation during the authentication process. An attacker could exploit this vulnerability by sending a series of malicious requests to an affected device. An exploit could allow the attacker to use the acquired session token to gain full administrator access to the affected device.

Published: Aug 21, 2019 Modified: Jun 17, 2026
CWE-287 CWE-287

CVSS Metrics

CVSSv3
Attack Vector: NETWORK Attack Complexity: LOW Privileges Required: NONE User Interaction: NONE Scope: UNCHANGED Confidentiality Impact: HIGH Integrity Impact: HIGH Availability Impact: HIGH

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected Products (6)

Vendor Product Version
cisco integrated_management_controller_supervisor * ≥ 2.2.0.3
cisco ucs_director * ≥ 6.6.0.0
cisco ucs_director * ≥ 6.7.0.0
cisco ucs_director 6.7\(0.0.67265\)
cisco ucs_director_express_for_big_data * ≥ 3.7.0.0
cisco ucs_director_express_for_big_data 3.6.0.0

GitHub Security Advisory GHSA-6j24-rh4h-rq7f

A vulnerability in the web-based management interface of Cisco Integrated Management Controller ...

Risk Scores

CVSS Score 9.8 / 10
EPSS Score 75.86%

Top 1% most likely to be exploited

Threat Score 72 / 100

Data Sources

NVD EPSS GitHub