CVE-2019-1900: Cisco Integrated Management Controller Unauthenticated Denial of Service Vulnerability
A vulnerability in the web server of Cisco Integrated Management Controller (IMC) could allow an unauthenticated, remote attacker to cause the web server process to crash, causing a denial of service (DoS) condition on an affected system. The vulnerability is due to insufficient validation of user-supplied input on the web interface. An attacker could exploit this vulnerability by submitting a crafted HTTP request to certain endpoints of the affected software. A successful exploit could allow an attacker to cause the web server to crash. Physical access to the device may be required for a restart.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-1900?
CVE-2019-1900 is a vulnerability in the web server of Cisco Integrated Management Controller (IMC) that could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected system.
How does CVE-2019-1900 impact Cisco Unified Computing System?
Cisco Unified Computing System version 4.0(1c)hs3 is affected by CVE-2019-1900, which could cause the web server process to crash and result in a denial of service (DoS) condition.
How does CVE-2019-1900 impact Cisco Integrated Management Controller Supervisor?
Cisco Integrated Management Controller Supervisor versions between 4.0.0.0 and 4.0(2f) are affected by CVE-2019-1900, which could cause the web server process to crash and result in a denial of service (DoS) condition.
Is Cisco Ucs C125 M5 vulnerable to CVE-2019-1900?
No, Cisco Ucs C125 M5 is not vulnerable to CVE-2019-1900.
Is Cisco Ucs C4200 vulnerable to CVE-2019-1900?
No, Cisco Ucs C4200 is not vulnerable to CVE-2019-1900.
Is Cisco Ucs S3260 vulnerable to CVE-2019-1900?
No, Cisco Ucs S3260 is not vulnerable to CVE-2019-1900.
How can I fix CVE-2019-1900?
Cisco has released a security advisory with the necessary patches and mitigations for CVE-2019-1900. You should update your affected systems with the latest available patches to mitigate this vulnerability.
Where can I find more information about CVE-2019-1900?
You can find more information about CVE-2019-1900 on the Cisco Security Advisory page at https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190821-imc-dos