Cisco Unified Computing System vulnerabilities
63 known vulnerabilities affecting cisco/cisco_unified_computing_system.
Total CVEs
63
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL2HIGH20MEDIUM40LOW1
Vulnerabilities
Page 2 of 4
CVE-2019-1962P3HIGHCVSS 7.5≥ unspecified, < 8.4(1)2019-08-28
CVE-2019-1962 [HIGH] CWE-20 CVE-2019-1962: A vulnerability in the Cisco Fabric Services component of Cisco NX-OS Software could allow an unauth
A vulnerability in the Cisco Fabric Services component of Cisco NX-OS Software could allow an unauthenticated, remote attacker to cause process crashes, which can result in a denial of service (DoS) condition on an affected system. The vulnerability is due to insufficient validation of TCP packets when processed by the Cisco Fabric Services over IP (CFSo
nvd
CVE-2019-1900P3HIGHCVSS 7.5≥ unspecified, < 4.0(2f)2019-08-21
CVE-2019-1900 [HIGH] CWE-476 CVE-2019-1900: A vulnerability in the web server of Cisco Integrated Management Controller (IMC) could allow an una
A vulnerability in the web server of Cisco Integrated Management Controller (IMC) could allow an unauthenticated, remote attacker to cause the web server process to crash, causing a denial of service (DoS) condition on an affected system. The vulnerability is due to insufficient validation of user-supplied input on the web interface. An attacker could e
nvd
CVE-2021-34736P3HIGHCVSS 7.5vn/a2021-10-21
CVE-2021-34736 [HIGH] CWE-20 CVE-2021-34736: A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC
A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) Software could allow an unauthenticated, remote attacker to cause the web-based management interface to unexpectedly restart. The vulnerability is due to insufficient input validation on the web-based management interface. An attacker could exploit thi
nvd
CVE-2019-1966P3HIGHCVSS 7.8≥ unspecified, < 4.0(2a)2019-08-30
CVE-2019-1966 [HIGH] CWE-264 CVE-2019-1966: A vulnerability in a specific CLI command within the local management (local-mgmt) context for Cisco
A vulnerability in a specific CLI command within the local management (local-mgmt) context for Cisco UCS Fabric Interconnect Software could allow an authenticated, local attacker to gain elevated privileges as the root user on an affected device. The vulnerability is due to extraneous subcommand options present for a specific CLI command within the loca
nvd
CVE-2019-1632P3HIGHCVSS 8.0v4.02019-06-20
CVE-2019-1632 [HIGH] CWE-352 CVE-2019-1632: A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC
A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) could allow an authenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack and perform arbitrary actions on an affected device. The vulnerability is due to insufficient CSRF protections for the web-based management interface of
nvd
CVE-2026-20099P3MEDIUMCVSS 6.7v4.0(4h)v4.1(1a)+85 more2026-02-25
CVE-2026-20099 [MEDIUM] CWE-78 CVE-2026-20099: A vulnerability in the web-based management interface of Cisco FXOS Software and Cisco UCS Mana
A vulnerability in the web-based management interface of Cisco FXOS Software and Cisco UCS Manager Software could allow an authenticated, local attacker with administrative privileges to perform command injection attacks on an affected system and elevate privileges to root.
This vulnerability is due to insufficient input validation of command argume
nvd
CVE-2020-3241P3MEDIUMCVSS 6.5vn/a2020-06-18
CVE-2020-3241 [MEDIUM] CWE-22 CVE-2020-3241: A vulnerability in the orchestration tasks of Cisco UCS Director could allow an authenticated, remot
A vulnerability in the orchestration tasks of Cisco UCS Director could allow an authenticated, remote attacker to perform a path traversal attack on an affected device. The vulnerability is due to insufficient validation of user-supplied input on the web-based management interface. An attacker could exploit this vulnerability by creating a task with sp
nvd
CVE-2025-20317P3HIGHCVSS 7.1v4.0(1a)v3.2(3n)+250 more2025-08-27
CVE-2025-20317 [HIGH] CWE-601 CVE-2025-20317: A vulnerability in the Virtual Keyboard Video Monitor (vKVM) connection handling of Cisco Integrated
A vulnerability in the Virtual Keyboard Video Monitor (vKVM) connection handling of Cisco Integrated Management Controller (IMC) could allow an unauthenticated, remote attacker to redirect a user to a malicious website.
This vulnerability is due to insufficient verification of vKVM endpoints. An attacker could exploit this vulnerability by persuading
nvd
CVE-2026-20010P3HIGHCVSS 7.4v4.3(4e)v4.3(6b)+11 more2026-02-25
CVE-2026-20010 [HIGH] CWE-805 CVE-2026-20010: A vulnerability in the Link Layer Discovery Protocol (LLDP) feature of Cisco NX-OS Software could al
A vulnerability in the Link Layer Discovery Protocol (LLDP) feature of Cisco NX-OS Software could allow an unauthenticated, adjacent attacker to cause the LLDP process to restart, which could cause an affected device to reload unexpectedly.
This vulnerability is due to improper handling of specific fields in an LLDP frame. An attacker could exploit t
nvd
CVE-2019-1627P3MEDIUMCVSS 6.5≥ unspecified, < 4.0(4b)2019-06-20
CVE-2019-1627 [MEDIUM] CWE-78 CVE-2019-1627: A vulnerability in the Server Utilities of Cisco Integrated Management Controller (IMC) could allow
A vulnerability in the Server Utilities of Cisco Integrated Management Controller (IMC) could allow an authenticated, remote attacker to gain unauthorized access to sensitive user information from the configuration data that is stored on the affected system. The vulnerability is due to insufficient protection of data in the configuration file. An attack
nvd
CVE-2019-1963P3MEDIUMCVSS 6.5≥ unspecified, < 8.4(1)2019-08-28
CVE-2019-1963 [MEDIUM] CWE-20 CVE-2019-1963: A vulnerability in the Simple Network Management Protocol (SNMP) input packet processor of Cisco FXO
A vulnerability in the Simple Network Management Protocol (SNMP) input packet processor of Cisco FXOS Software and Cisco NX-OS Software could allow an authenticated, remote attacker to cause the SNMP application on an affected device to restart unexpectedly. The vulnerability is due to improper validation of Abstract Syntax Notation One (ASN.1)-encoded
nvd
CVE-2023-20015P3MEDIUMCVSS 6.7vn/a2023-02-23
CVE-2023-20015 [MEDIUM] CWE-78 CVE-2023-20015: A vulnerability in the CLI of Cisco Firepower 4100 Series, Cisco Firepower 9300 Security Appliances,
A vulnerability in the CLI of Cisco Firepower 4100 Series, Cisco Firepower 9300 Security Appliances, and Cisco UCS 6200, 6300, 6400, and 6500 Series Fabric Interconnects could allow an authenticated, local attacker to inject unauthorized commands. This vulnerability is due to insufficient input validation of commands supplied by the user. An attacker
nvd
CVE-2023-20200P3MEDIUMCVSS 6.3v3.1(1e)v3.1(1g)+92 more2023-08-23
CVE-2023-20200 [MEDIUM] CWE-835 CVE-2023-20200: A vulnerability in the Simple Network Management Protocol (SNMP) service of Cisco FXOS Software for
A vulnerability in the Simple Network Management Protocol (SNMP) service of Cisco FXOS Software for Firepower 4100 Series and Firepower 9300 Security Appliances and of Cisco UCS 6300 Series Fabric Interconnects could allow an authenticated, remote attacker to cause a denial of service (DoS) condition on an affected device.
This vulnerability is due t
nvd
CVE-2019-1629P3MEDIUMCVSS 5.3v4.02019-06-20
CVE-2019-1629 [MEDIUM] CWE-306 CVE-2019-1629: A vulnerability in the configuration import utility of Cisco Integrated Management Controller (IMC)
A vulnerability in the configuration import utility of Cisco Integrated Management Controller (IMC) could allow an unauthenticated, remote attacker to have write access and upload arbitrary data to the filesystem. The vulnerability is due to a failure to delete temporarily uploaded files. An attacker could exploit this vulnerability by crafting a malic
nvd
CVE-2020-26063P3MEDIUMCVSS 5.4v4.0(1a)v3.2(3n)+41 more2024-11-18
CVE-2020-26063 [MEDIUM] CWE-269 CVE-2020-26063: A vulnerability in the API endpoints of Cisco Integrated Management Controller could allow an a
A vulnerability in the API endpoints of Cisco Integrated Management Controller could allow an authenticated, remote attacker to bypass authorization and take actions on a vulnerable system without authorization.
The vulnerability is due to improper authorization checks on API endpoints. An attacker could exploit this vulnerability by sending malicio
nvd
CVE-2019-1879P4MEDIUMCVSS 6.7v4.02019-06-20
CVE-2019-1879 [MEDIUM] CWE-78 CVE-2019-1879: A vulnerability in the CLI of Cisco Integrated Management Controller (IMC) could allow an authentica
A vulnerability in the CLI of Cisco Integrated Management Controller (IMC) could allow an authenticated, local attacker to inject arbitrary commands that are executed with root privileges. The vulnerability is due to insufficient validation of user-supplied input at the CLI. An attacker could exploit this vulnerability by authenticating with the admini
nvd
CVE-2025-20295P3MEDIUMCVSS 6.0v4.0(1a)v4.1(1d)+103 more2025-08-27
CVE-2025-20295 [MEDIUM] CWE-78 CVE-2025-20295: A vulnerability in the CLI of Cisco UCS Manager Software could allow an authenticated, local attacke
A vulnerability in the CLI of Cisco UCS Manager Software could allow an authenticated, local attacker with administrative privileges to read or create a file or overwrite any file on the file system of the underlying operating system of an affected device, including system files.
This vulnerability is due to insufficient input validation of command
nvd
CVE-2019-1631P4MEDIUMCVSS 5.3≥ unspecified, < 4.0(4b)2019-06-20
CVE-2019-1631 [MEDIUM] CWE-306 CVE-2019-1631: A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC
A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) could allow an unauthenticated, remote attacker to access potentially sensitive system usage information. The vulnerability is due to a lack of proper data protection mechanisms. An attacker could exploit this vulnerability by sending a crafted HTTP r
nvd
CVE-2020-26062P4MEDIUMCVSS 5.3v4.0(1a)v3.2(3n)+40 more2024-11-18
CVE-2020-26062 [MEDIUM] CWE-203 CVE-2020-26062: A vulnerability in Cisco Integrated Management Controller could allow an unauthenticated, remot
A vulnerability in Cisco Integrated Management Controller could allow an unauthenticated, remote attacker to enumerate valid usernames within the vulnerable application.
The vulnerability is due to differences in authentication responses sent back from the application as part of an authentication attempt. An attacker could exploit this vulnerability
nvd
CVE-2025-20292P4MEDIUMCVSS 4.4v4.0(4c)v4.0(2b)+82 more2025-08-27
CVE-2025-20292 [MEDIUM] CWE-78 CVE-2025-20292: A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated, local attacker to e
A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated, local attacker to execute a command injection attack on the underlying operating system of an affected device. To exploit this vulnerability, the attacker must have valid user credentials on the affected device.
This vulnerability is due to insufficient validation of us
nvd