CVE-2020-3173OS Command Injection in Cisco Unified Computing System

Severity
7.8HIGHNVD
EPSS
0.2%
top 52.88%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 26
Latest updateMay 24

Description

A vulnerability in the local management (local-mgmt) CLI of Cisco UCS Manager Software could allow an authenticated, local attacker to execute arbitrary commands on the underlying operating system (OS) on an affected device. The vulnerability is due to insufficient input validation of command arguments. An attacker could exploit this vulnerability by including crafted arguments to specific commands on the local management CLI. A successful exploit could allow the attacker to execute arbitrary co

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages2 packages

NVDcisco/ucs_manager4.04.0\(4c\)+1
CVEListV5cisco/cisco_unified_computing_systemunspecifiedn/a

🔴Vulnerability Details

2
GHSA
GHSA-v2mf-949v-6qrh: A vulnerability in the local management (local-mgmt) CLI of Cisco UCS Manager Software could allow an authenticated, local attacker to execute arbitra2022-05-24
CVEList
Cisco UCS Manager Software Local Management CLI Command Injection Vulnerability2020-02-26

📋Vendor Advisories

1
Cisco
Cisco UCS Manager Software Local Management CLI Command Injection Vulnerability2020-02-26
CVE-2020-3173 — OS Command Injection in Cisco | cvebase