CVE-2015-6355
published 2015-11-04CVE-2015-6355: The web interface in Cisco Unified Computing System (UCS) 2.2(5b)A on blade servers allows remote attackers to obtain potentially sensitive version information…
PriorityP423medium5CVSS 2.0
AVNACLAuNCPINAN
EPSS
1.69%
74.7th percentile
The web interface in Cisco Unified Computing System (UCS) 2.2(5b)A on blade servers allows remote attackers to obtain potentially sensitive version information by visiting an unspecified URL, aka Bug ID CSCuw87226.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | unified_computing_system | — | — |
| cisco | unified_computing_system_blade_server | — | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
vendor_cisco5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco Unified Computing System Blade Server Information Disclosure Vulnerability
vendor_cisco·2015-11-02·CVSS 5.0
CVE-2015-6355 [MEDIUM] CWE-200 Cisco Unified Computing System Blade Server Information Disclosure Vulnerability
Cisco Unified Computing System Blade Server Information Disclosure Vulnerability
A vulnerability in the web interface of the Cisco Unified Computing System (UCS) Blade Server could allow an unauthenticated, remote attacker to obtain information about the UCS software version.
The vulnerability is due to the verbose output that is returned when a specific URL is submitted to an affected system. An attacker could exploit this vulnerability by browsing to a specific URL. A successful exploit could allow an attacker to obtain information from the UCS. The information could be used for reconnaissance attacks.
Cisco has not released software updates that address this vulnerability. There are no workarounds that mitigate this vulnerability.
This advisory is available at the following link: h
Cisco
Cisco Unified Computing System Blade Server Information Disclosure Vulnerability
vendor_cisco
CVE-2015-6355 Cisco Unified Computing System Blade Server Information Disclosure Vulnerability
CVE-2015-6355: Cisco Unified Computing System Blade Server Information Disclosure Vulnerability
A vulnerability in the web interface of the Cisco Unified Computing System (UCS) Blade Server could allow an unauthenticated, remote attacker to obtain information about the UCS software version. The vulnerability is due to the verbose output that is returned when a specific URL is submitted to an affected system. An attacker could exploit this vulnerability by browsing to a specific URL. A successful exploit could allow an attacker to obtain information from the UCS. The information could be used for reconnaissance attacks. Cisco has not released software updates that address this vulnerability. There are no
CWE: CWE-200, CWE-200
Bug IDs: CSCuw87226
GHSA
GHSA-fgcg-572p-3m99: The web interface in Cisco Unified Computing System (UCS) 2
ghsa_unreviewed·2022-05-14
CVE-2015-6355 [MEDIUM] CWE-200 GHSA-fgcg-572p-3m99: The web interface in Cisco Unified Computing System (UCS) 2
The web interface in Cisco Unified Computing System (UCS) 2.2(5b)A on blade servers allows remote attackers to obtain potentially sensitive version information by visiting an unspecified URL, aka Bug ID CSCuw87226.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2015-11-04
Published