vendor:
Cisco UCS-IMC Supervisor
by:
Fatih Sencer
7.5
CVSS
HIGH
Authentication Bypass
287
CWE
Product Name: Cisco UCS-IMC Supervisor
Affected Version From:
Affected Version To: 2.2.0.0
Patch Exists: YES
Related CWE: CVE-2019-1937
CPE: a:cisco_systems:ucs-imc_supervisor:2.2.0.0
Platforms Tested:
2019
Cisco UCS-IMC Supervisor 2.2.0.0 – Authentication Bypass
This exploit allows an attacker to bypass authentication in Cisco UCS-IMC Supervisor version 2.2.0.0 and earlier. By sending a specially crafted request to the /app/ui/ClientServlet?apiName=GetUserInfo endpoint, the attacker can gain unauthorized access to the system.
Mitigation:
Upgrade to version 2.2.1.0 or later.