Cisco Integrated Management Controller Information Disclosure Vulnerability
CVE-2019-1631

5.3MEDIUM

Key Information:

Vendor
Cisco
Vendor
CVE Published:
20 June 2019

Badges

👾 Exploit Exists

Summary

A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) could allow an unauthenticated, remote attacker to access potentially sensitive system usage information. The vulnerability is due to a lack of proper data protection mechanisms. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected device. A successful exploit could allow an attacker to view sensitive system data.

Affected Version(s)

Cisco Unified Computing System (Management Software) < 4.0(4b)

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • 👾

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

.