Cisco Integrated Management Controller Supervisor vulnerabilities

27 known vulnerabilities affecting cisco/integrated_management_controller_supervisor.

Total CVEs
27
CISA KEV
1
actively exploited
Public exploits
4
Exploited in wild
1
Severity breakdown
CRITICAL5HIGH16MEDIUM6

Vulnerabilities

Page 2 of 2
CVE-2018-0149MEDIUMCVSS 4.8v2.1\(0.2\)v2.2\(0.2\)2018-06-07
CVE-2018-0149 [MEDIUM] CWE-79 CVE-2018-0149: A vulnerability in the web-based management interface of Cisco Integrated Management Controller Supe A vulnerability in the web-based management interface of Cisco Integrated Management Controller Supervisor Software and Cisco UCS Director Software could allow an authenticated, remote attacker to conduct a Document Object Model-based (DOM-based), stored cross-site scripting (XSS) attack against a user of the web-based management interface of an affect
nvd
CVE-2017-6619HIGHCVSS 8.8v3.0\(1c\)2017-04-20
CVE-2017-6619 [HIGH] CWE-20 CVE-2017-6619: A vulnerability in the web-based GUI of Cisco Integrated Management Controller (IMC) 3.0(1c) could a A vulnerability in the web-based GUI of Cisco Integrated Management Controller (IMC) 3.0(1c) could allow an authenticated, remote attacker to execute arbitrary commands on an affected system. The vulnerability exists because the affected software does not sufficiently sanitize user-supplied HTTP input. An attacker could exploit this vulnerability by send
nvd
CVE-2017-6616HIGHCVSS 8.8v3.0\(1c\)2017-04-20
CVE-2017-6616 [HIGH] CWE-20 CVE-2017-6616: A vulnerability in the web-based GUI of Cisco Integrated Management Controller (IMC) 3.0(1c) could a A vulnerability in the web-based GUI of Cisco Integrated Management Controller (IMC) 3.0(1c) could allow an authenticated, remote attacker to execute arbitrary code on an affected system. The vulnerability exists because the affected software does not sufficiently sanitize specific values that are received as part of a user-supplied HTTP request. An atta
nvd
CVE-2017-6618MEDIUMCVSS 5.4v3.0\(1c\)2017-04-20
CVE-2017-6618 [MEDIUM] CWE-79 CVE-2017-6618: A vulnerability in the web-based GUI of Cisco Integrated Management Controller (IMC) 3.0(1c) could a A vulnerability in the web-based GUI of Cisco Integrated Management Controller (IMC) 3.0(1c) could allow an authenticated, remote attacker to perform a cross-site scripting (XSS) attack. The vulnerability is due to insufficient validation of user-supplied input by the affected software. An attacker could exploit this vulnerability by persuading an auth
nvd
CVE-2017-6617MEDIUMCVSS 5.4v3.0\(1c\)2017-04-20
CVE-2017-6617 [MEDIUM] CWE-287 CVE-2017-6617: A vulnerability in the session identification management functionality of the web-based GUI of Cisco A vulnerability in the session identification management functionality of the web-based GUI of Cisco Integrated Management Controller (IMC) 3.0(1c) could allow an unauthenticated, remote attacker to hijack a valid user session on an affected system. The vulnerability exists because the affected software does not assign a new session identifier to a us
nvd
CVE-2015-6399MEDIUMCVSS 6.8v1.0.0.0v1.0.0.12015-12-15
CVE-2015-6399 [MEDIUM] CWE-399 CVE-2015-6399: The Supervisor 1.0.0.0 and 1.0.0.1 in Cisco Integrated Management Controller (IMC) before 2.0(9) all The Supervisor 1.0.0.0 and 1.0.0.1 in Cisco Integrated Management Controller (IMC) before 2.0(9) allows remote authenticated users to cause a denial of service (IP interface outage) via crafted parameters in an HTTP request, aka Bug ID CSCuv38286.
nvd
CVE-2015-6259CRITICALCVSS 9.4≤ 1.0.0.02015-09-04
CVE-2015-6259 [CRITICAL] CWE-20 CVE-2015-6259: The JavaServer Pages (JSP) component in Cisco Integrated Management Controller (IMC) Supervisor befo The JavaServer Pages (JSP) component in Cisco Integrated Management Controller (IMC) Supervisor before 1.0.0.1 and UCS Director (formerly Cloupia Unified Infrastructure Controller) before 5.2.0.1 allows remote attackers to write to arbitrary files via crafted HTTP requests, aka Bug IDs CSCus36435 and CSCus62625.
nvd