CVE-2015-0633
published 2015-02-26CVE-2015-0633: The Integrated Management Controller (IMC) in Cisco Unified Computing System (UCS) 1.4(7h) and earlier on C-Series servers allows remote attackers to bypass…
PriorityP430medium6.8CVSS 2.0
AVAACLAuNCNIPAC
EPSS
1.04%
60.1th percentile
The Integrated Management Controller (IMC) in Cisco Unified Computing System (UCS) 1.4(7h) and earlier on C-Series servers allows remote attackers to bypass intended access restrictions by sending crafted DHCP response packets on the local network, aka Bug ID CSCuf52876.
Affected
23 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | unified_computing_system | — | — |
| cisco | unified_computing_system | — | — |
| cisco | unified_computing_system | — | — |
| cisco | unified_computing_system | — | — |
| cisco | unified_computing_system | — | — |
| cisco | unified_computing_system | — | — |
| cisco | unified_computing_system | — | — |
| cisco | unified_computing_system | — | — |
| cisco | unified_computing_system | — | — |
| cisco | unified_computing_system | — | — |
| cisco | unified_computing_system | — | — |
| cisco | unified_computing_system | — | — |
| cisco | unified_computing_system | — | — |
| cisco | unified_computing_system | — | — |
| cisco | unified_computing_system | — | — |
| cisco | unified_computing_system | — | — |
| cisco | unified_computing_system | — | — |
| cisco | unified_computing_system | — | — |
| cisco | unified_computing_system | — | — |
| cisco | unified_computing_system | — | — |
| cisco | unified_computing_system | — | — |
| cisco | unified_computing_system | — | — |
| cisco | unified_computing_system | — | — |
CVSS provenance
nvdv2.06.8MEDIUMAV:A/AC:L/Au:N/C:N/I:P/A:C
vendor_cisco6.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco UCS C-Series Integrated Management Controller Denial of Service Vulnerability
vendor_cisco·2015-02-25·CVSS 6.8
CVE-2015-0633 [MEDIUM] CWE-20 Cisco UCS C-Series Integrated Management Controller Denial of Service Vulnerability
Cisco UCS C-Series Integrated Management Controller Denial of Service Vulnerability
A vulnerability in the Cisco Integrated Management Controller (IMC) of Cisco Unified Computing System (UCS) C-Series Servers could allow an unauthenticated, adjacent attacker to access specific controls on the Cisco IMC on an affected device.
The vulnerability is due to insufficient input validation for DHCP response packets. An attacker could exploit this vulnerability by sending crafted DHCP packets to the device.
Cisco has confirmed the vulnerability in a security notice; however, software updates are not available.
To exploit this vulnerability, an attacker must be on the same broadcast or collision domain as the targeted device to send crafted DHCP packets to the device. This access requirement de
GHSA
GHSA-w33q-rw95-475p: The Integrated Management Controller (IMC) in Cisco Unified Computing System (UCS) 1
ghsa_unreviewed·2022-05-14
CVE-2015-0633 [MEDIUM] CWE-20 GHSA-w33q-rw95-475p: The Integrated Management Controller (IMC) in Cisco Unified Computing System (UCS) 1
The Integrated Management Controller (IMC) in Cisco Unified Computing System (UCS) 1.4(7h) and earlier on C-Series servers allows remote attackers to bypass intended access restrictions by sending crafted DHCP response packets on the local network, aka Bug ID CSCuf52876.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2015-0633http://tools.cisco.com/security/center/viewAlert.x?alertId=37575http://www.securityfocus.com/bid/72760http://www.securityfocus.com/bid/85711http://www.securitytracker.com/id/1031796http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2015-0633http://tools.cisco.com/security/center/viewAlert.x?alertId=37575http://www.securityfocus.com/bid/72760http://www.securityfocus.com/bid/85711http://www.securitytracker.com/id/1031796
2015-02-26
Published