CVE-2015-4183
published 2015-06-17CVE-2015-4183: Cisco UCS Central Software 1.2(1a) allows local users to gain privileges for OS command execution via a crafted CLI parameter, aka Bug ID CSCut32795.
PriorityP431high7.2CVSS 2.0
AVLACLAuNCCICAC
EPSS
0.58%
43.9th percentile
Cisco UCS Central Software 1.2(1a) allows local users to gain privileges for OS command execution via a crafted CLI parameter, aka Bug ID CSCut32795.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | unified_computing_system | — | — |
CVSS provenance
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
vendor_cisco7.2HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco UCS Central Software Command-Line Interface Command Injection Vulnerability
vendor_cisco·2015-06-15·CVSS 7.2
CVE-2015-4183 [HIGH] CWE-78 Cisco UCS Central Software Command-Line Interface Command Injection Vulnerability
Cisco UCS Central Software Command-Line Interface Command Injection Vulnerability
A vulnerability in the command-line interface (CLI) of Cisco UCS Central Software could allow an authenticated, local attacker to inject arbitrary commands that are executed with elevated privileges on the underlying operating system.
The vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by authenticating to the device and submitting crafted commands to the affected parameter in the CLI. An exploit could allow the attacker to read, write, and overwrite any file on the system or execute arbitrary code.
Cisco has confirmed the vulnerability and released software updates.
To exploit this vulnerability, an attacker must authenticate and have local access to a
GHSA
GHSA-6x43-g9fr-c293: Cisco UCS Central Software 1
ghsa_unreviewed·2022-05-17
CVE-2015-4183 [HIGH] CWE-78 GHSA-6x43-g9fr-c293: Cisco UCS Central Software 1
Cisco UCS Central Software 1.2(1a) allows local users to gain privileges for OS command execution via a crafted CLI parameter, aka Bug ID CSCut32795.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2015-06-17
Published