CVE-2015-6259
published 2015-09-04CVE-2015-6259: The JavaServer Pages (JSP) component in Cisco Integrated Management Controller (IMC) Supervisor before 1.0.0.1 and UCS Director (formerly Cloupia Unified…
PriorityP349critical9.4CVSS 2.0
AVNACLAuNCNICAC
EPSS
2.82%
85.1th percentile
The JavaServer Pages (JSP) component in Cisco Integrated Management Controller (IMC) Supervisor before 1.0.0.1 and UCS Director (formerly Cloupia Unified Infrastructure Controller) before 5.2.0.1 allows remote attackers to write to arbitrary files via crafted HTTP requests, aka Bug IDs CSCus36435 and CSCus62625.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | integrated_management_controller_supervisor | <= 1.0.0.0 | — |
| cisco | integrated_management_controller_supervisor_and_cisco_ucs_director | — | — |
| cisco | unified_computing_system_director | <= 5.2.0.0 | — |
| cisco | unified_computing_system_director | — | — |
| cisco | unified_computing_system_director | — | — |
| cisco | unified_computing_system_director | — | — |
| cisco | unified_computing_system_director | — | — |
| cisco | unified_computing_system_director | — | — |
| cisco | unified_computing_system_director | — | — |
| cisco | unified_computing_system_director | — | — |
| cisco | unified_computing_system_director | — | — |
| cisco | unified_computing_system_director | — | — |
CVSS provenance
nvdv2.09.4CRITICALAV:N/AC:L/Au:N/C:N/I:C/A:C
vendor_cisco7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco Integrated Management Controller Supervisor and Cisco UCS Director Remote File Overwrite Vulnerability
vendor_cisco·2015-09-02·CVSS 7.8
CVE-2015-6259 [HIGH] CWE-22 Cisco Integrated Management Controller Supervisor and Cisco UCS Director Remote File Overwrite Vulnerability
Cisco Integrated Management Controller Supervisor and Cisco UCS Director Remote File Overwrite Vulnerability
Cisco Integrated Management Controller (IMC) Supervisor and Cisco UCS Director contain a remote file overwrite vulnerability that could allow an unauthenticated, remote attacker to overwrite arbitrary system files, resulting in system instability or a denial of service (DoS) condition.
Cisco has released software updates that address this vulnerability.
Workarounds that mitigate this vulnerability are not available.
This advisory is available at the following link:
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20150902-cimcs
Cisco
Cisco Integrated Management Controller Supervisor and Cisco UCS Director Remote File Overwrite Vulnerability
vendor_cisco
CVE-2015-6259 Cisco Integrated Management Controller Supervisor and Cisco UCS Director Remote File Overwrite Vulnerability
CVE-2015-6259: Cisco Integrated Management Controller Supervisor and Cisco UCS Director Remote File Overwrite Vulnerability
Cisco Integrated Management Controller (IMC) Supervisor and Cisco UCS Director contain a remote file overwrite vulnerability that could allow an unauthenticated, remote attacker to overwrite arbitrary system files, resulting in system instability or a denial of service (DoS) condition. Cisco has released software updates that address this vulnerability.
CWE: CWE-22, CWE-22
Bug IDs: CSCus36435, CSCus62625, CSCus36435, CSCus62625
GHSA
GHSA-gjjm-x2xg-8xgc: The JavaServer Pages (JSP) component in Cisco Integrated Management Controller (IMC) Supervisor before 1
ghsa_unreviewed·2022-05-17
CVE-2015-6259 [HIGH] CWE-20 GHSA-gjjm-x2xg-8xgc: The JavaServer Pages (JSP) component in Cisco Integrated Management Controller (IMC) Supervisor before 1
The JavaServer Pages (JSP) component in Cisco Integrated Management Controller (IMC) Supervisor before 1.0.0.1 and UCS Director (formerly Cloupia Unified Infrastructure Controller) before 5.2.0.1 allows remote attackers to write to arbitrary files via crafted HTTP requests, aka Bug IDs CSCus36435 and CSCus62625.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2015-09-04
Published