cbcvebase.

Cisco Unified Computing System vulnerabilities

63 known vulnerabilities affecting cisco/cisco_unified_computing_system.

Total CVEs
63
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL2HIGH20MEDIUM40LOW1

Vulnerabilities

Page 1 of 4
CVE-2024-20356P2HIGHCVSS 8.7v3.0(1c)v3.0(1d)+117 more2024-04-24
CVE-2024-20356 [HIGH] CWE-78 CVE-2024-20356: A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) could allow an authenticated, remote attacker with Administrator-level privileges to perform command injection attacks on an affected system and elevate their privileges to root. This vulnerability is due to insufficient user input validation. An attac
nvd
CVE-2020-3470P2CRITICALCVSS 9.8vn/a2020-11-18
CVE-2020-3470 [CRITICAL] CWE-119 CVE-2020-3470: Multiple vulnerabilities in the API subsystem of Cisco Integrated Management Controller (IMC) could Multiple vulnerabilities in the API subsystem of Cisco Integrated Management Controller (IMC) could allow an unauthenticated, remote attacker to execute arbitrary code with root privileges. The vulnerabilities are due to improper boundary checks for certain user-supplied input. An attacker could exploit these vulnerabilities by sending a crafted HTTP
nvd
CVE-2026-20093P2CRITICALCVSS 9.8v4.0(2g)v3.1(2i)+139 more2026-04-01
CVE-2026-20093 [CRITICAL] CWE-20 CVE-2026-20093: A vulnerability in the change password functionality of Cisco Integrated Management Controller (IMC) A vulnerability in the change password functionality of Cisco Integrated Management Controller (IMC) could allow an unauthenticated, remote attacker to bypass authentication and gain access to the system as Admin. This vulnerability is due to incorrect handling of password change requests. An attacker could exploit this vulnerability by sending a
nvd
CVE-2026-20094P2HIGHCVSS 8.8v4.0(2g)v3.1(2i)+148 more2026-04-01
CVE-2026-20094 [HIGH] CWE-77 CVE-2026-20094: A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, rem A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with read-only privileges to perform command injection attacks on an affected system and execute arbitrary commands as the root user. This vulnerability is due to improper validation of user-supplied input. An attacker could exploit this vu
nvd
CVE-2025-20261P2HIGHCVSS 8.8v4.0(1a)v3.2(3n)+140 more2025-06-04
CVE-2025-20261 [HIGH] CWE-923 CVE-2025-20261: A vulnerability in the SSH connection handling of Cisco Integrated Management Controller (IMC) for C A vulnerability in the SSH connection handling of Cisco Integrated Management Controller (IMC) for Cisco UCS B-Series, UCS C-Series, UCS S-Series, and UCS X-Series Servers could allow an authenticated, remote attacker to access internal services with elevated privileges. This vulnerability is due to insufficient restrictions on access to internal ser
nvd
CVE-2020-3371P3HIGHCVSS 8.8vn/a2020-11-06
CVE-2020-3371 [HIGH] CWE-78 CVE-2020-3371: A vulnerability in the web UI of Cisco Integrated Management Controller (IMC) could allow an authent A vulnerability in the web UI of Cisco Integrated Management Controller (IMC) could allow an authenticated, remote attacker to inject arbitrary code and execute arbitrary commands at the underlying operating system level. The vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by sending crafted commands to
nvd
CVE-2020-3119P3HIGHCVSS 8.8≥ unspecified, < 9.3(2)2020-02-05
CVE-2020-3119 [HIGH] CWE-787 CVE-2020-3119: A vulnerability in the Cisco Discovery Protocol implementation for Cisco NX-OS Software could allow A vulnerability in the Cisco Discovery Protocol implementation for Cisco NX-OS Software could allow an unauthenticated, adjacent attacker to execute arbitrary code or cause a reload on an affected device. The vulnerability exists because the Cisco Discovery Protocol parser does not properly validate input for certain fields in a Cisco Discovery Protocol
nvd
CVE-2020-3172P3HIGHCVSS 8.8≥ unspecified, < n/a2020-02-26
CVE-2020-3172 [HIGH] CWE-20 CVE-2020-3172: A vulnerability in the Cisco Discovery Protocol feature of Cisco FXOS Software and Cisco NX-OS Softw A vulnerability in the Cisco Discovery Protocol feature of Cisco FXOS Software and Cisco NX-OS Software could allow an unauthenticated, adjacent attacker to execute arbitrary code as root or cause a denial of service (DoS) condition on an affected device. The vulnerability exists because of insufficiently validated Cisco Discovery Protocol packet headers
nvd
CVE-2019-1907P3HIGHCVSS 8.8≥ unspecified, < 4.0(2f)2019-08-21
CVE-2019-1907 [HIGH] CWE-285 CVE-2019-1907: A vulnerability in the web server of Cisco Integrated Management Controller (IMC) could allow an aut A vulnerability in the web server of Cisco Integrated Management Controller (IMC) could allow an authenticated, remote attacker to set sensitive configuration values and gain elevated privileges. The vulnerability is due to improper handling of substring comparison operations that are performed by the affected software. An attacker could exploit this vu
nvd
CVE-2024-20295P3HIGHCVSS 8.8v3.0(1c)v3.0(1d)+161 more2024-04-24
CVE-2024-20295 [HIGH] CWE-78 CVE-2024-20295: A vulnerability in the CLI of the Cisco Integrated Management Controller (IMC) could allow an authen A vulnerability in the CLI of the Cisco Integrated Management Controller (IMC) could allow an authenticated, local attacker to perform command injection attacks on the underlying operating system and elevate privileges to root. To exploit this vulnerability, the attacker must have read-only or higher privileges on an affected device. This vulnerability
nvd
CVE-2019-1885P3HIGHCVSS 7.2≥ unspecified, < 3.0(4k)2019-08-21
CVE-2019-1885 [HIGH] CWE-78 CVE-2019-1885: A vulnerability in the Redfish protocol of Cisco Integrated Management Controller (IMC) could allow A vulnerability in the Redfish protocol of Cisco Integrated Management Controller (IMC) could allow an authenticated, remote attacker to inject and execute arbitrary commands with root privileges on an affected device. The vulnerability is due to insufficient validation of user-supplied input by the affected software. An attacker could exploit this vulner
nvd
CVE-2024-20365P3HIGHCVSS 7.2v4.1(2a)v4.1(2b)+41 more2024-10-02
CVE-2024-20365 [HIGH] CWE-77 CVE-2024-20365: A vulnerability in the Redfish API of Cisco UCS B-Series, Cisco UCS Managed C-Series, and Cisco UCS A vulnerability in the Redfish API of Cisco UCS B-Series, Cisco UCS Managed C-Series, and Cisco UCS X-Series Servers could allow an authenticated, remote attacker with administrative privileges to perform command injection attacks on an affected system and elevate privileges to root. This vulnerability is due to insufficient input validation. An attack
nvd
CVE-2019-1871P3HIGHCVSS 7.2≥ unspecified, < 3.0(4k)2019-08-21
CVE-2019-1871 [HIGH] CWE-119 CVE-2019-1871: A vulnerability in the Import Cisco IMC configuration utility of Cisco Integrated Management Control A vulnerability in the Import Cisco IMC configuration utility of Cisco Integrated Management Controller (IMC) could allow an authenticated, remote attacker to cause a denial of service (DoS) condition and implement arbitrary commands with root privileges on an affected device. The vulnerability is due to improper bounds checking by the import-config pro
nvd
CVE-2025-20294P3MEDIUMCVSS 6.5v4.0(1a)v4.1(1d)+103 more2025-08-27
CVE-2025-20294 [MEDIUM] CWE-78 CVE-2025-20294: Multiple vulnerabilities in the CLI and web-based management interface of Cisco UCS Manager Software Multiple vulnerabilities in the CLI and web-based management interface of Cisco UCS Manager Software could allow an authenticated, remote attacker with administrative privileges to perform command injection attacks on an affected system and elevate privileges to root. These vulnerabilities are due to insufficient input validation of command argument
nvd
CVE-2026-20095P3MEDIUMCVSS 6.5v4.0(2g)v3.1(2i)+148 more2026-04-01
CVE-2026-20095 [MEDIUM] CWE-77 CVE-2026-20095: A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, rem A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with admin-level privileges to perform command injection attacks on an affected system and execute arbitrary commands as the root user. This vulnerability is due to improper validation of user-supplied input. An attacker could exploit thi
nvd
CVE-2026-20096P3MEDIUMCVSS 6.5v4.0(2g)v3.1(2i)+148 more2026-04-01
CVE-2026-20096 [MEDIUM] CWE-77 CVE-2026-20096: A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, rem A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with admin-level privileges to perform command injection attacks on an affected system and execute arbitrary commands as the root user. This vulnerability is due to improper validation of user-supplied input. An attacker could exploit thi
nvd
CVE-2026-20097P3MEDIUMCVSS 6.5v4.0(2g)v3.1(2i)+142 more2026-04-01
CVE-2026-20097 [MEDIUM] CWE-787 CVE-2026-20097: A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, rem A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with admin-level privileges to execute arbitrary code as the root user. This vulnerability is due to improper validation of user-supplied input to the web-based management interface. An attacker could exploit this vulnerability by sending
nvd
CVE-2026-20036P3MEDIUMCVSS 6.5v4.0(4h)v4.1(1a)+93 more2026-02-25
CVE-2026-20036 [MEDIUM] CWE-78 CVE-2026-20036: A vulnerability in the CLI and web-based management interface of Cisco UCS Manager Software could al A vulnerability in the CLI and web-based management interface of Cisco UCS Manager Software could allow an authenticated, remote attacker with valid administrative privileges to execute arbitrary commands on the underlying operating system of an affected device. This vulnerability is due to insufficient input validation of command arguments that are
nvd
CVE-2020-3173P3HIGHCVSS 7.8≥ unspecified, < n/a2020-02-26
CVE-2020-3173 [HIGH] CWE-78 CVE-2020-3173: A vulnerability in the local management (local-mgmt) CLI of Cisco UCS Manager Software could allow a A vulnerability in the local management (local-mgmt) CLI of Cisco UCS Manager Software could allow an authenticated, local attacker to execute arbitrary commands on the underlying operating system (OS) on an affected device. The vulnerability is due to insufficient input validation of command arguments. An attacker could exploit this vulnerability by inc
nvd
CVE-2019-1908P3HIGHCVSS 7.5≥ unspecified, < 3.0(4k)2019-08-21
CVE-2019-1908 [HIGH] CWE-200 CVE-2019-1908: A vulnerability in the Intelligent Platform Management Interface (IPMI) implementation of Cisco Inte A vulnerability in the Intelligent Platform Management Interface (IPMI) implementation of Cisco Integrated Management Controller (IMC) could allow an unauthenticated, remote attacker to view sensitive system information. The vulnerability is due to insufficient security restrictions imposed by the affected software. A successful exploit could allow the
nvd
Cisco Unified Computing System vulnerabilities | cvebase