cbcvebase.
CVE-2015-6435
published 2016-01-22

CVE-2015-6435: An unspecified CGI script in Cisco FX-OS before 1.1.2 on Firepower 9000 devices and Cisco Unified Computing System (UCS) Manager before 2.2(4b), 2.2(5) before…

PriorityP267critical9.8CVSS 3.0
AVNACLPRNUINSUCHIHAH
EPSS
8.68%
94.5th percentile
An unspecified CGI script in Cisco FX-OS before 1.1.2 on Firepower 9000 devices and Cisco Unified Computing System (UCS) Manager before 2.2(4b), 2.2(5) before 2.2(5a), and 3.0 before 3.0(2e) allows remote attackers to execute arbitrary shell commands via a crafted HTTP request, aka Bug ID CSCur90888.

Affected

87 ranges· showing 25
VendorProductVersion rangeFixed in
ciscofirepower_extensible_operating_system
ciscofirepower_extensible_operating_system
ciscofirepower_extensible_operating_system
ciscounified_computing_system
ciscounified_computing_system
ciscounified_computing_system
ciscounified_computing_system
ciscounified_computing_system
ciscounified_computing_system
ciscounified_computing_system
ciscounified_computing_system
ciscounified_computing_system
ciscounified_computing_system
ciscounified_computing_system
ciscounified_computing_system
ciscounified_computing_system
ciscounified_computing_system
ciscounified_computing_system
ciscounified_computing_system
ciscounified_computing_system
ciscounified_computing_system
ciscounified_computing_system
ciscounified_computing_system
ciscounified_computing_system
ciscounified_computing_system

Detection & IOCsextracted from sources · hover to see the quote

  • The vulnerability is triggered by a crafted HTTP request to an unspecified CGI script on Cisco UCS Manager or Cisco Firepower 9000; detection should focus on anomalous or shell-metacharacter-containing HTTP requests targeting CGI endpoints on these devices.
  • The root cause is unprotected shell command invocation from within a CGI script (CWE-78 OS Command Injection); inspect CGI HTTP request parameters for shell injection characters (e.g., ;, |, &&, $(), backticks).
  • No authentication is required to exploit this vulnerability; any unauthenticated HTTP request to the affected CGI endpoint carrying shell injection payloads should be treated as suspicious.
  • Cisco Bug IDs CSCur90888 and CSCux10615 are associated with this vulnerability; use these identifiers when querying Cisco TAC logs, PSIRT feeds, or internal ticketing systems for affected asset correlation.
  • ·The specific CGI script path is not publicly disclosed, limiting the ability to write precise path-based detection rules.
  • ·Affected versions span multiple UCS Manager trains (pre-2.2(4b), pre-2.2(5a), pre-3.0(2e)) and FX-OS pre-1.1.2; ensure version-scoping is applied when deploying detections to avoid false positives on patched devices.

CVSS provenance

nvdv3.09.8CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
vendor_cisco10.0CRITICAL
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.