CVE-2016-6402
published 2016-09-18CVE-2016-6402: UCS Manager and UCS 6200 Fabric Interconnects in Cisco Unified Computing System (UCS) through 3.0(2d) allow local users to obtain OS root access via crafted…
PriorityP338high7.8CVSS 3.0
AVLACLPRLUINSUCHIHAH
EPSS
0.36%
28.3th percentile
UCS Manager and UCS 6200 Fabric Interconnects in Cisco Unified Computing System (UCS) through 3.0(2d) allow local users to obtain OS root access via crafted CLI input, aka Bug ID CSCuz91263.
Affected
29 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | unified_computing_system | — | — |
| cisco | unified_computing_system | — | — |
| cisco | unified_computing_system | — | — |
| cisco | unified_computing_system | — | — |
| cisco | unified_computing_system | — | — |
| cisco | unified_computing_system | — | — |
| cisco | unified_computing_system | — | — |
| cisco | unified_computing_system | — | — |
| cisco | unified_computing_system | — | — |
| cisco | unified_computing_system | — | — |
| cisco | unified_computing_system | — | — |
| cisco | unified_computing_system | — | — |
| cisco | unified_computing_system | — | — |
| cisco | unified_computing_system | — | — |
| cisco | unified_computing_system | — | — |
| cisco | unified_computing_system | — | — |
| cisco | unified_computing_system | — | — |
| cisco | unified_computing_system | — | — |
| cisco | unified_computing_system | — | — |
| cisco | unified_computing_system | — | — |
| cisco | unified_computing_system | — | — |
| cisco | unified_computing_system | — | — |
| cisco | unified_computing_system | — | — |
| cisco | unified_computing_system | — | — |
| cisco | unified_computing_system | — | — |
CVSS provenance
nvdv3.07.8HIGHCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
vendor_cisco6.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco Unified Computing System Command Line Interface Privilege Escalation Vulnerability
vendor_cisco·2016-09-14·CVSS 6.8
CVE-2016-6402 [MEDIUM] CWE-264 Cisco Unified Computing System Command Line Interface Privilege Escalation Vulnerability
Cisco Unified Computing System Command Line Interface Privilege Escalation Vulnerability
A vulnerability in the command-line interface (CLI) of the Cisco Unified Computing System (UCS) Manager and UCS 6200 Series Fabric Interconnects could allow an authenticated, local attacker to access the underlying operating system with the privileges of the root user.
The vulnerability is due to insufficient sanitization of user-supplied input at the CLI. An attacker could exploit this vulnerability by bypassing policy restrictions and executing commands on the underlying operating system. The user needs to log in to the device with valid user credentials to exploit this vulnerability.
Cisco has not released software updates that address this vulnerability. Workarounds that mitigate this vulnerabil
Cisco
Cisco Unified Computing System Command Line Interface Privilege Escalation Vulnerability
vendor_cisco
CVE-2016-6402 Cisco Unified Computing System Command Line Interface Privilege Escalation Vulnerability
CVE-2016-6402: Cisco Unified Computing System Command Line Interface Privilege Escalation Vulnerability
A vulnerability in the command-line interface (CLI) of the Cisco Unified Computing System (UCS) Manager and UCS 6200 Series Fabric Interconnects could allow an authenticated, local attacker to access the underlying operating system with the privileges of the root user. The vulnerability is due to insufficient sanitization of user-supplied input at the CLI. An attacker could exploit this vulnerability by bypassing policy restrictions and executing commands on the underlying operating system. The user needs to log in to the device with valid user credentials to exploit this vulnerability. Cisco has not released software updates that address this vulnerability.
CWE: CWE-264, CWE-264
Bug IDs
GHSA
GHSA-3mqx-q3cf-pfj3: UCS Manager and UCS 6200 Fabric Interconnects in Cisco Unified Computing System (UCS) through 3
ghsa_unreviewed·2022-05-17
CVE-2016-6402 [HIGH] GHSA-3mqx-q3cf-pfj3: UCS Manager and UCS 6200 Fabric Interconnects in Cisco Unified Computing System (UCS) through 3
UCS Manager and UCS 6200 Fabric Interconnects in Cisco Unified Computing System (UCS) through 3.0(2d) allow local users to obtain OS root access via crafted CLI input, aka Bug ID CSCuz91263.
No detection rules found.
No writeups or analysis indexed.
http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160914-ucshttp://www.securityfocus.com/bid/92956http://www.securitytracker.com/id/1036831http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160914-ucshttp://www.securityfocus.com/bid/92956http://www.securitytracker.com/id/1036831
2016-09-18
Published