Severity
8.8HIGH
EPSS
30.7%
top 3.28%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 15
Latest updateMay 24

Description

Multiple vulnerabilities in the REST API of Cisco UCS Director and Cisco UCS Director Express for Big Data may allow a remote attacker to bypass authentication or conduct directory traversal attacks on an affected device. For more information about these vulnerabilities, see the Details section of this advisory.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages3 packages

NVDcisco/ucs_director18 versions+17

🔴Vulnerability Details

2
GHSA
GHSA-rr8j-3q27-jmv3: Multiple vulnerabilities in the REST API of Cisco UCS Director and Cisco UCS Director Express for Big Data may allow a remote attacker to bypass authe2022-05-24
CVEList
Multiple Vulnerabilities in Cisco UCS Director and Cisco UCS Director Express for Big Data2020-04-15

📋Vendor Advisories

1
Cisco
Multiple Vulnerabilities in Cisco UCS Director and Cisco UCS Director Express for Big Data2020-04-15
CVE-2020-3251 (HIGH CVSS 8.8) | Multiple vulnerabilities in the RES | cvebase.io