cisco unified-computing-system CVE-2019-1966 is a vulnerability in Cisco Unified Computing System
Published on August 30, 2019

Cisco Unified Computing System Fabric Interconnect root Privilege Escalation Vulnerability
A vulnerability in a specific CLI command within the local management (local-mgmt) context for Cisco UCS Fabric Interconnect Software could allow an authenticated, local attacker to gain elevated privileges as the root user on an affected device. The vulnerability is due to extraneous subcommand options present for a specific CLI command within the local-mgmt context. An attacker could exploit this vulnerability by authenticating to an affected device, entering the local-mgmt context, and issuing a specific CLI command and submitting user input. A successful exploit could allow the attacker to execute arbitrary operating system commands as root on an affected device. The attacker would need to have valid user credentials for the device.

Vendor Advisory NVD

Weakness Type

Permissions, Privileges, and Access Controls

Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.


Products Associated with CVE-2019-1966

Want to know whenever a new CVE is published for Cisco Unified Computing System? stack.watch will email you.

 

Affected Versions

Cisco Unified Computing System (Managed):

Exploit Probability

EPSS
0.23%
Percentile
45.90%

EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.