CVE-2019-1908

A vulnerability in the Intelligent Platform Management Interface (IPMI) implementation of Cisco Integrated Management Controller (IMC) could allow an unauthenticated, remote attacker to view sensitive system information. The vulnerability is due to insufficient security restrictions imposed by the affected software. A successful exploit could allow the attacker to view sensitive information that belongs to other users. The attacker could then use this information to conduct additional attacks.

Data: Cisco advisories · Cisco CSAF · NVD CVEs · NVD CPEs · CISA KEV · EPSS

SeverityHIGH
CVSS7.5
EPSS0.88% EPSS medium
CWECWE-200
KEV
Published
Modified

Products with public affected evidence

Product Advisory Affected evidence
Cisco Unified Computing System (Standalone) cisco-sa-20190821-imc-infodisc structured affected CSAF product_status
Cisco Unified Computing System (Management Software) cisco-sa-20190821-imc-infodisc structured affected CSAF product_status