← Back to browse · API

CVE-2019-1938

Severity
CRITICAL
CVSS
9.8
EPSS
0.04566
Risk score
40.8
CISA KEV
No
PoC
No
Published
2019-08-21
Modified
2024-11-19
First seen
2026-08-07
Aliases
EUVD-2019-10495, GHSA-99XV-4FXW-WM5H
Products
Cisco:Cisco Unified Computing System Director unspecified <6.7.3.0
Sources
euvd EUVD-2019-10495

Description

A vulnerability in the web-based management interface of Cisco UCS Director and Cisco UCS Director Express for Big Data could allow an unauthenticated, remote attacker to bypass authentication and execute arbitrary actions with administrator privileges on an affected system. The vulnerability is due to improper authentication request handling. An attacker could exploit this vulnerability by sending crafted HTTP requests to an affected device. A successful exploit could allow an unprivileged attacker to access and execute arbitrary actions through certain APIs.

References