Vulnslist

find the latest Cisco vulnerabilities

Cisco Integrated Management Controller Arbitrary File Write Vulnerability

cisco-sa-20190619-imc-filewrite · Medium · Published · Updated

A vulnerability in the configuration import utility of Cisco Integrated Management Controller (IMC) could allow an unauthenticated, remote attacker to have write access and upload arbitrary data to the filesystem. The vulnerability is due to a failure to delete temporarily uploaded files. An attacker could exploit this vulnerability by crafting a malicious file and uploading it to the affected device. An exploit could allow the attacker to fill up the filesystem or upload malicious scripts. There are no workarounds that address this vulnerability. This advisory is available at the following link: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190619-imc-filewrite

Workarounds

There are no workarounds that address this vulnerability.

CVEsCVE-2019-1629
Cisco Bug IDsCSCvo35982
CVSS ScoreBase 5.3
Base 5.3 CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N/E:X/RL:X/RC:X
Product Names From Source
Cisco Unified Computing System (Management Software)

Related Products

Product CVE Evidence
Cisco Unified Computing System (Management Software) CVE-2019-1629 Cisco OpenVuln