HIGH

CVE-2019-19642

CVSS v3

8.8

HIGH

EPSS Score

26.0%

exploit probability

CISA KEV

No

known exploited

Exploitation

SSVC status

Description

On SuperMicro X8STi-F motherboards with IPMI firmware 2.06 and BIOS 02.68, the Virtual Media feature allows OS Command Injection by authenticated attackers who can send HTTP requests to the IPMI IP address. This requires a POST to /rpc/setvmdrive.asp with shell metacharacters in ShareHost or ShareName. The attacker can achieve a persistent backdoor.

Technical details

Published
12/8/2019

Frequently asked questions

What is CVE-2019-19642?

On SuperMicro X8STi-F motherboards with IPMI firmware 2.06 and BIOS 02.68, the Virtual Media feature allows OS Command Injection by authenticated attackers who can send HTTP requests to the IPMI IP address. This requires a POST to /rpc/setvmdrive.asp with shell metacharacters in ShareHost or ShareName. The attacker can achieve a persistent backdoor.

Is CVE-2019-19642 actively exploited?

Active exploitation of CVE-2019-19642 has not been confirmed. The EPSS score is 26.0%, indicating the estimated probability of exploitation in the next 30 days.

What is the CVSS score for CVE-2019-19642?

CVE-2019-19642 has a CVSS v3 base score of 8.8 (HIGH severity).

Is CVE-2019-19642 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.