cbcvebase.

Cisco Unified Computing System vulnerabilities

63 known vulnerabilities affecting cisco/cisco_unified_computing_system.

Total CVEs
63
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL2HIGH20MEDIUM40LOW1

Vulnerabilities

Page 3 of 4
CVE-2023-20016P4MEDIUMCVSS 6.5vn/a2023-02-23
CVE-2023-20016 [MEDIUM] CWE-321 CVE-2023-20016: A vulnerability in the backup configuration feature of Cisco UCS Manager Software and in the configu A vulnerability in the backup configuration feature of Cisco UCS Manager Software and in the configuration export feature of Cisco FXOS Software could allow an unauthenticated attacker with access to a backup file to decrypt sensitive information stored in the full state and configuration backup files. This vulnerability is due to a weakness in the
nvd
CVE-2026-20085P4MEDIUMCVSS 6.1v4.0(2g)v3.1(2i)+142 more2026-04-01
CVE-2026-20085 [MEDIUM] CWE-79 CVE-2026-20085: A vulnerability in the web-based management interface of Cisco IMC could allow an unauthenticated, r A vulnerability in the web-based management interface of Cisco IMC could allow an unauthenticated, remote attacker to conduct a reflected XSS attack against a user of the interface. This vulnerability is due to insufficient validation of user input. An attacker could exploit this vulnerability by persuading a user of an affected interface to click a
nvd
CVE-2021-1397P4MEDIUMCVSS 6.1vn/a2021-05-06
CVE-2021-1397 [MEDIUM] CWE-601 CVE-2021-1397: A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) Software could allow an unauthenticated, remote attacker to redirect a user to a malicious web page. This vulnerability is due to improper input validation of the parameters in an HTTP request. An attacker could exploit this vulnerability by persuadin
nvd
CVE-2025-20342P4MEDIUMCVSS 5.4v4.0(1a)v3.2(3n)+250 more2025-08-27
CVE-2025-20342 [MEDIUM] CWE-80 CVE-2025-20342: A vulnerability in the Virtual Keyboard Video Monitor (vKVM) connection handling of Cisco Integrated A vulnerability in the Virtual Keyboard Video Monitor (vKVM) connection handling of Cisco Integrated Management Controller (IMC) could allow an authenticated, remote attacker with low privileges to conduct a stored cross-site scripting (XSS) attack against a user of the interface. This vulnerability is due to insufficient validation of user-supplied
nvd
CVE-2023-20228P4MEDIUMCVSS 6.1v3.1(1d)v3.1(2b)+84 more2023-08-16
CVE-2023-20228 [MEDIUM] CWE-80 CVE-2023-20228: A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. This vulnerability is due to insufficient validation of user input. An attacker could exploit this vulnerability by persua
nvd
CVE-2025-20296P4MEDIUMCVSS 5.4v4.0(1a)v4.1(1d)+101 more2025-08-27
CVE-2025-20296 [MEDIUM] CWE-79 CVE-2025-20296: A vulnerability in the web-based management interface of Cisco UCS Manager Software could allow an a A vulnerability in the web-based management interface of Cisco UCS Manager Software could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface. This vulnerability is due to insufficient validation of user-supplied input by the web-based management interface of an affected syste
nvd
CVE-2020-3242P4MEDIUMCVSS 4.9vn/a2020-06-18
CVE-2020-3242 [MEDIUM] CWE-200 CVE-2020-3242: A vulnerability in the REST API of Cisco UCS Director could allow an authenticated, remote attacker A vulnerability in the REST API of Cisco UCS Director could allow an authenticated, remote attacker with administrative privileges to obtain confidential information from an affected device. The vulnerability exists because confidential information is returned as part of an API response. An attacker could exploit this vulnerability by sending a crafted
nvd
CVE-2024-20397P4MEDIUMCVSS 5.2v4.0(4c)v4.0(2b)+69 more2024-12-04
CVE-2024-20397 [MEDIUM] CWE-284 CVE-2024-20397: A vulnerability in the bootloader of Cisco NX-OS Software could allow an unauthenticated attacker wi A vulnerability in the bootloader of Cisco NX-OS Software could allow an unauthenticated attacker with physical access to an affected device, or an authenticated, local attacker with administrative credentials, to bypass NX-OS image signature verification. This vulnerability is due to insecure bootloader settings. An attacker could exploit this vul
nvd
CVE-2024-20344P4MEDIUMCVSS 5.3vN/A2024-02-29
CVE-2024-20344 [MEDIUM] CWE-400 CVE-2024-20344: A vulnerability in system resource management in Cisco UCS 6400 and 6500 Series Fabric Interconnects A vulnerability in system resource management in Cisco UCS 6400 and 6500 Series Fabric Interconnects that are in Intersight Managed Mode (IMM) could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on the Device Console UI of an affected device. This vulnerability is due to insufficient rate-limiting of TCP conn
nvd
CVE-2025-20290P4MEDIUMCVSS 5.5v4.0(4c)v4.0(2b)+84 more2025-08-27
CVE-2025-20290 [MEDIUM] CWE-200 CVE-2025-20290: A vulnerability in the logging feature of Cisco NX-OS Software for Cisco Nexus 3000 Series Switches, A vulnerability in the logging feature of Cisco NX-OS Software for Cisco Nexus 3000 Series Switches, Cisco Nexus 9000 Series Switches in standalone NX-OS mode, Cisco UCS 6400 Fabric Interconnects, Cisco UCS 6500 Series Fabric Interconnects, and Cisco UCS 9108 100G Fabric Interconnects could allow an authenticated, local attacker access to sensitive
nvd
CVE-2024-20294P4MEDIUMCVSS 6.6v3.1(1e)v3.1(1g)+98 more2024-02-29
CVE-2024-20294 [MEDIUM] CWE-805 CVE-2024-20294: A vulnerability in the Link Layer Discovery Protocol (LLDP) feature of Cisco FXOS Software and Cisco A vulnerability in the Link Layer Discovery Protocol (LLDP) feature of Cisco FXOS Software and Cisco NX-OS Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper handling of specific fields in an LLDP frame. An attacker could exploit this vu
nvd
CVE-2026-20089P4MEDIUMCVSS 4.8v4.0(2g)v3.1(2i)+148 more2026-04-01
CVE-2026-20089 [MEDIUM] CWE-79 CVE-2026-20089: A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, rem A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with administrative privileges to conduct a stored XSS attack against a user of the interface. This vulnerability is due to insufficient validation of user input. An attacker could exploit this vulnerability by persuading a user of an aff
nvd
CVE-2026-20090P4MEDIUMCVSS 4.8v4.0(2g)v3.1(2i)+148 more2026-04-01
CVE-2026-20090 [MEDIUM] CWE-79 CVE-2026-20090: A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, rem A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with administrative privileges to conduct a stored XSS attack against a user of the interface. This vulnerability is due to insufficient validation of user input. An attacker could exploit this vulnerability by persuading a user of an aff
nvd
CVE-2026-20088P4MEDIUMCVSS 4.8v4.0(2g)v3.1(2i)+142 more2026-04-01
CVE-2026-20088 [MEDIUM] CWE-79 CVE-2026-20088: A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, rem A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with administrative privileges to conduct a stored XSS attack against a user of the interface. This vulnerability is due to insufficient validation of user input. An attacker could exploit this vulnerability by persuading a user of an aff
nvd
CVE-2026-20087P4MEDIUMCVSS 4.8v4.0(2g)v3.1(2i)+148 more2026-04-01
CVE-2026-20087 [MEDIUM] CWE-79 CVE-2026-20087: A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, rem A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with administrative privileges to conduct a stored XSS attack against a user of the interface. This vulnerability is due to insufficient validation of user input. An attacker could exploit this vulnerability by persuading a user of an aff
nvd
CVE-2019-1628P4MEDIUMCVSS 5.5≥ unspecified, < 4.0(4b)2019-06-20
CVE-2019-1628 [MEDIUM] CWE-191 CVE-2019-1628: A vulnerability in the web server of Cisco Integrated Management Controller (IMC) could allow an aut A vulnerability in the web server of Cisco Integrated Management Controller (IMC) could allow an authenticated, local attacker to cause a buffer overflow, resulting in a denial of service (DoS) condition on an affected device. The vulnerability is due to incorrect bounds checking. An attacker could exploit this vulnerability by sending a crafted HTTP
nvd
CVE-2026-20037P4MEDIUMCVSS 4.4v4.0(4c)v4.0(2b)+88 more2026-02-25
CVE-2026-20037 [MEDIUM] CWE-250 CVE-2026-20037: A vulnerability in the NX-OS CLI privilege levels of Cisco UCS Manager Software could allow an authe A vulnerability in the NX-OS CLI privilege levels of Cisco UCS Manager Software could allow an authenticated, local attacker with read-only privileges to modify files and perform unauthorized actions on an affected system. This vulnerability exists because unnecessary privileges are given to the user. An attacker could exploit this vulnerability by
nvd
CVE-2019-1630P4MEDIUMCVSS 5.5v4.02019-06-20
CVE-2019-1630 [MEDIUM] CWE-119 CVE-2019-1630: A vulnerability in the firmware signature checking program of Cisco Integrated Management Controller A vulnerability in the firmware signature checking program of Cisco Integrated Management Controller (IMC) could allow an authenticated, local attacker to cause a buffer overflow, resulting in a denial of service (DoS) condition. The vulnerability is due to insufficient checking of an input buffer. An attacker could exploit this vulnerability by passi
nvd
CVE-2026-20091P4MEDIUMCVSS 4.8v4.0(4h)v4.1(1a)+83 more2026-02-25
CVE-2026-20091 [MEDIUM] CWE-79 CVE-2026-20091: A vulnerability in the web-based management interface of Cisco FXOS Software and Cisco UCS Manager S A vulnerability in the web-based management interface of Cisco FXOS Software and Cisco UCS Manager Software could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface. This vulnerability is due to insufficient validation of user-supplied input by the web-based management interf
nvd
CVE-2021-1592P4MEDIUMCVSS 4.3vn/a2021-08-25
CVE-2021-1592 [MEDIUM] CWE-664 CVE-2021-1592: A vulnerability in the way Cisco UCS Manager software handles SSH sessions could allow an authentica A vulnerability in the way Cisco UCS Manager software handles SSH sessions could allow an authenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper resource management for established SSH sessions. An attacker could exploit this vulnerability by opening a significant number
nvd
Cisco Unified Computing System vulnerabilities | cvebase