CVE-2019-12634: Cisco Integrated Management Controller Supervisor, Cisco UCS Director, and Cisco UCS Director Express for Big Data Denial of Service Vulnerability
A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) Supervisor, Cisco UCS Director, and Cisco UCS Director Express for Big Data could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition. The vulnerability is due to a missing authentication check in an API call. An attacker who can send a request to an affected system could cause all currently authenticated users to be logged off. Repeated exploitation could cause the inability to maintain a session in the web-based management portal.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-12634?
CVE-2019-12634 is a vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) Supervisor, Cisco UCS Director, and Cisco UCS Director Express for Big Data.
How does CVE-2019-12634 affect Cisco Integrated Management Controller Supervisor?
CVE-2019-12634 affects Cisco Integrated Management Controller Supervisor versions 2.2.0.3 to 2.2.0.6.
How does CVE-2019-12634 affect Cisco UCS Director?
CVE-2019-12634 affects Cisco UCS Director versions 6.7.0.0 to 6.7.2.0.
How does CVE-2019-12634 affect Cisco UCS Director Express for Big Data?
CVE-2019-12634 affects Cisco UCS Director Express for Big Data versions 3.7.0.0 to 3.7.2.0.
What is the severity of CVE-2019-12634?
CVE-2019-12634 has a severity rating of 7.5 (High).
How can I fix CVE-2019-12634?
To fix CVE-2019-12634, Cisco has released software updates for the affected products. It is recommended to update to the latest available version.