Cisco Integrated Management Controller(IMC)是美国思科(Cisco)公司的一套用于对UCS(统一计算系统)进行管理的软件。该软件支持HTTP、SSH访问等,并可对服务器进行开机、关机和重启等操作。 Cisco IMC中的命令行界面存在操作系统命令注入漏洞,该漏洞源于程序没有充分验证用户提交的输入。本地攻击者可通过进行身份验证并提交特制的输入利用该漏洞注入任意命令并获取root权限。以下产品及版本受到影响:Cisco UCS C-Series和S-Series Se
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Cisco | Cisco Unified Computing System E-Series Software (UCSE) | unspecified ~ 3.0(4k) | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2019-1864 | Cisco Integrated Management Controller Command Injection Vulnerability | |
| CVE-2019-12623 | Cisco Enterprise Network Functions Virtualization Infrastructure Software File Enumeration | |
| CVE-2019-12622 | Cisco RoomOS Software Privilege Escalation Vulnerability | |
| CVE-2019-12621 | Cisco HyperFlex Static SSL Key Vulnerability | |
| CVE-2019-12634 | Cisco Integrated Management Controller Supervisor, Cisco UCS Director, and Cisco UCS Direc | |
| CVE-2019-12627 | Cisco Firepower Threat Defense Software Information Disclosure Vulnerability | |
| CVE-2019-12626 | Cisco Unified Contact Center Express Stored Cross-Site Scripting Vulnerability | |
| CVE-2019-12624 | Cisco IOS XE NGWC Legacy Wireless Device Manager GUI Cross-Site Request Forgery Vulnerabil | |
| CVE-2019-1850 | Cisco Integrated Management Controller Command Injection Vulnerability | |
| CVE-2019-1839 | Cisco Remote PHY Device Software Command Injection Vulnerability | |
| CVE-2019-1634 | Cisco Integrated Management Controller Command Injection Vulnerability | |
| CVE-2019-1871 | Cisco Integrated Management Controller Buffer Overflow Vulnerability | |
| CVE-2019-1865 | Cisco Integrated Management Controller Command Injection Vulnerability | |
| CVE-2019-1938 | Cisco UCS Director and Cisco UCS Director Express for Big Data API Authentication Bypass V | |
| CVE-2019-1863 | Cisco Integrated Management Controller Privilege Escalation Vulnerability | |
| CVE-2019-1900 | Cisco Integrated Management Controller Unauthenticated Denial of Service Vulnerability | |
| CVE-2019-1896 | Cisco Integrated Management Controller CSR Generation Command Injection Vulnerability | |
| CVE-2019-1885 | Cisco Integrated Management Controller Command Injection Vulnerability | |
| CVE-2019-1937 | Cisco Integrated Management Controller Supervisor, Cisco UCS Director, and Cisco UCS Direc | |
| CVE-2019-1936 | Cisco Integrated Management Controller Supervisor, Cisco UCS Director, and Cisco UCS Direc |
Showing top 20 of 27 CVEs. View all on vendor page → →
No comments yet