cisco-sa-20190821-ucsd-authbypass: Cisco UCS Director and Cisco UCS Director Express for Big Data API Authentication Bypass Vulnerability
A vulnerability in the web-based management interface of Cisco UCS Director and Cisco UCS Director Express for Big Data could allow an unauthenticated, remote attacker to bypass authentication and execute arbitrary actions with administrator privileges on an affected system. The vulnerability is due to improper authentication request handling. An attacker could exploit this vulnerability by sending crafted HTTP requests to an affected device. A successful exploit could allow an unprivileged attacker to access and execute arbitrary actions through certain APIs.
Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.
This advisory is available at the following link: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190821-ucsd-authbypass
Affected Software
Event History
Frequently Asked Questions
What is the severity of cisco-sa-20190821-ucsd-authbypass?
The severity of cisco-sa-20190821-ucsd-authbypass is considered high due to the potential for unauthenticated remote access and administration privileges.
How do I fix cisco-sa-20190821-ucsd-authbypass?
To fix cisco-sa-20190821-ucsd-authbypass, update your Cisco UCS Director or Cisco UCS Director Express for Big Data to the latest patched version provided by Cisco.
What systems are affected by cisco-sa-20190821-ucsd-authbypass?
cisco-sa-20190821-ucsd-authbypass affects Cisco UCS Director and Cisco UCS Director Express for Big Data.
What actions can an attacker perform with cisco-sa-20190821-ucsd-authbypass?
An attacker exploiting cisco-sa-20190821-ucsd-authbypass can execute arbitrary actions with administrator privileges on the affected systems.
Is there a workaround for cisco-sa-20190821-ucsd-authbypass?
There are no specific workarounds recommended for cisco-sa-20190821-ucsd-authbypass; applying the necessary updates is the advised mitigation strategy.