cisco-sa-20190821-ucsd-authbypass: Cisco UCS Director and Cisco UCS Director Express for Big Data API Authentication Bypass Vulnerability

Published Aug 21, 2019
·
Updated

A vulnerability in the web-based management interface of Cisco UCS Director and Cisco UCS Director Express for Big Data could allow an unauthenticated, remote attacker to bypass authentication and execute arbitrary actions with administrator privileges on an affected system. The vulnerability is due to improper authentication request handling. An attacker could exploit this vulnerability by sending crafted HTTP requests to an affected device. A successful exploit could allow an unprivileged attacker to access and execute arbitrary actions through certain APIs.

Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.

This advisory is available at the following link: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190821-ucsd-authbypass

Affected Software

2 affected components
Cisco UCS Director
Cisco UCS Director Express for Big Data

Event History

Aug 21, 2019
Advisory Published
04:00 PM
Data Sourced
04:00 PM
DescriptionSeverityWeaknessAffected Software

Child vulnerabilities

Contains the following vulnerabilities.

Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of cisco-sa-20190821-ucsd-authbypass?

The severity of cisco-sa-20190821-ucsd-authbypass is considered high due to the potential for unauthenticated remote access and administration privileges.

2

How do I fix cisco-sa-20190821-ucsd-authbypass?

To fix cisco-sa-20190821-ucsd-authbypass, update your Cisco UCS Director or Cisco UCS Director Express for Big Data to the latest patched version provided by Cisco.

3

What systems are affected by cisco-sa-20190821-ucsd-authbypass?

cisco-sa-20190821-ucsd-authbypass affects Cisco UCS Director and Cisco UCS Director Express for Big Data.

4

What actions can an attacker perform with cisco-sa-20190821-ucsd-authbypass?

An attacker exploiting cisco-sa-20190821-ucsd-authbypass can execute arbitrary actions with administrator privileges on the affected systems.

5

Is there a workaround for cisco-sa-20190821-ucsd-authbypass?

There are no specific workarounds recommended for cisco-sa-20190821-ucsd-authbypass; applying the necessary updates is the advised mitigation strategy.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203