CVE-2015-4259
published 2015-07-10CVE-2015-4259: The Integrated Management Controller on Cisco Unified Computing System (UCS) C servers with software 1.5(3) and 1.6(0.16) has a default SSL certificate, which…
PriorityP420medium4.3CVSS 2.0
AVNACMAuNCPINAN
EPSS
0.78%
51.7th percentile
The Integrated Management Controller on Cisco Unified Computing System (UCS) C servers with software 1.5(3) and 1.6(0.16) has a default SSL certificate, which makes it easier for man-in-the-middle attackers to bypass cryptographic protection mechanisms by leveraging knowledge of a private key, aka Bug IDs CSCum56133 and CSCum56177.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | unified_computing_system | — | — |
| cisco | unified_computing_system | — | — |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
vendor_cisco4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-cq2w-9r84-5hfm: The Integrated Management Controller on Cisco Unified Computing System (UCS) C servers with software 1
ghsa_unreviewed·2022-05-17
CVE-2015-4259 [MEDIUM] GHSA-cq2w-9r84-5hfm: The Integrated Management Controller on Cisco Unified Computing System (UCS) C servers with software 1
The Integrated Management Controller on Cisco Unified Computing System (UCS) C servers with software 1.5(3) and 1.6(0.16) has a default SSL certificate, which makes it easier for man-in-the-middle attackers to bypass cryptographic protection mechanisms by leveraging knowledge of a private key, aka Bug IDs CSCum56133 and CSCum56177.
Cisco
Cisco Unified Computing System C-Series Servers Man-in-the-Middle Vulnerability
vendor_cisco·2015-07-09·CVSS 4.3
CVE-2015-4259 [MEDIUM] CWE-310 Cisco Unified Computing System C-Series Servers Man-in-the-Middle Vulnerability
Cisco Unified Computing System C-Series Servers Man-in-the-Middle Vulnerability
A vulnerability in the Cisco Integrated Management Controller of the Cisco Unified Computing System (UCS) C-Series Servers could allow an unauthenticated, remote attacker to perform a man-in-the-middle attack against the affected device.
The vulnerability is due to improper validation of the SSL certificate used to manage the device. An attacker could exploit this vulnerability by using the default SSL certificate to intercept, decrypt, read, and write information.
Cisco has confirmed the vulnerability; however, software updates are not available.
A successful exploit of this vulnerability could allow the attacker to impact the confidentiality of information transmitted by the device by decrypting encrypte
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2015-07-10
Published