CVE-2019-1871: Cisco Integrated Management Controller Buffer Overflow Vulnerability
A vulnerability in the Import Cisco IMC configuration utility of Cisco Integrated Management Controller (IMC) could allow an authenticated, remote attacker to cause a denial of service (DoS) condition and implement arbitrary commands with root privileges on an affected device. The vulnerability is due to improper bounds checking by the import-config process. An attacker could exploit this vulnerability by sending malicious packets to an affected device. When the packets are processed, an exploitable buffer overflow condition may occur. A successful exploit could allow the attacker to implement arbitrary code on the affected device with elevated privileges.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-1871?
CVE-2019-1871 is a vulnerability in the Import Cisco IMC configuration utility of Cisco Integrated Management Controller (IMC) that could allow an attacker to cause a denial of service (DoS) and execute arbitrary commands with root privileges.
How severe is CVE-2019-1871?
CVE-2019-1871 has a severity rating of 7.2 (critical).
Which software versions are affected by CVE-2019-1871?
The affected software versions for CVE-2019-1871 are Cisco Unified Computing System 4.0(1c)hs3, Cisco Integrated Management Controller Supervisor versions between 3.0.0.0 and 3.0(4k), and Cisco Integrated Management Controller Supervisor versions between 4.0.0.0 and 4.0(4b).
How can an attacker exploit CVE-2019-1871?
An attacker can exploit CVE-2019-1871 by using the Import Cisco IMC configuration utility to cause a denial of service (DoS) and execute arbitrary commands with root privileges.
Where can I find more information about CVE-2019-1871?
You can find more information about CVE-2019-1871 on the Cisco Security Advisory page: https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190821-imc-bo