cisco unified-computing-system CVE-2019-1900 is a vulnerability in Cisco Unified Computing System
Published on August 21, 2019

Cisco Integrated Management Controller Unauthenticated Denial of Service Vulnerability
A vulnerability in the web server of Cisco Integrated Management Controller (IMC) could allow an unauthenticated, remote attacker to cause the web server process to crash, causing a denial of service (DoS) condition on an affected system. The vulnerability is due to insufficient validation of user-supplied input on the web interface. An attacker could exploit this vulnerability by submitting a crafted HTTP request to certain endpoints of the affected software. A successful exploit could allow an attacker to cause the web server to crash. Physical access to the device may be required for a restart.

Vendor Advisory NVD

Weakness Type

NULL Pointer Dereference

A NULL pointer dereference occurs when the application dereferences a pointer that it expects to be valid, but is NULL, typically causing a crash or exit. NULL pointer dereference issues can occur through a number of flaws, including race conditions, and simple programming omissions.


Products Associated with CVE-2019-1900

Want to know whenever a new CVE is published for Cisco Unified Computing System? stack.watch will email you.

 

Affected Versions

Cisco Unified Computing System (Management Software):

Exploit Probability

EPSS
0.27%
Percentile
50.12%

EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.