CVE-2019-1863: Cisco Integrated Management Controller Privilege Escalation Vulnerability
A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) Software could allow an authenticated, remote attacker to make unauthorized changes to the system configuration. The vulnerability is due to insufficient authorization enforcement. An attacker could exploit this vulnerability by sending a crafted HTTP request to the affected software. A successful exploit could allow a user with read-only privileges to change critical system configurations using administrator privileges.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-1863?
CVE-2019-1863 is a vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) Software that could allow an authenticated, remote attacker to make unauthorized changes to the system configuration.
How severe is CVE-2019-1863?
CVE-2019-1863 has a severity rating of 8.1 (critical).
Which systems are affected by CVE-2019-1863?
CVE-2019-1863 affects Cisco Unified Computing System (UCS) versions 4.0(1c)hs3, Cisco Integrated Management Controller Supervisor versions 1.5.0.0 to 1.5(9g), 2.0.0.0 to 2.0(13o), 3.0.0.0 to 3.0(4k), and 4.0.0.0 to 4.0(4b).
How do I fix CVE-2019-1863?
To fix CVE-2019-1863, Cisco recommends upgrading to a fixed software release as mentioned in the Cisco Security Advisory.
Where can I find more information about CVE-2019-1863?
You can find more information about CVE-2019-1863 in the Cisco Security Advisory: https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190821-imc-privilege