cbcvebase.

Cisco Integrated Management Controller Supervisor vulnerabilities

27 known vulnerabilities affecting cisco/integrated_management_controller_supervisor.

Total CVEs
27
CISA KEV
1
actively exploited
Public exploits
4
Exploited in wild
1
Severity breakdown
CRITICAL5HIGH16MEDIUM6

Vulnerabilities

Page 2 of 2
CVE-2019-12634P3HIGHCVSS 7.5≥ 2.2.0.3, ≤ 2.2.0.62019-08-21
CVE-2019-12634 [HIGH] CWE-264 CVE-2019-12634: A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) Supervisor, Cisco UCS Director, and Cisco UCS Director Express for Big Data could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition. The vulnerability is due to a missing authentication check in an API call. An att
nvd
CVE-2018-15404P4MEDIUMCVSS 6.5v2.1\(0.0\)2018-10-05
CVE-2018-15404 [MEDIUM] CWE-399 CVE-2018-15404: A vulnerability in the web interface of Cisco Integrated Management Controller (IMC) Supervisor and A vulnerability in the web interface of Cisco Integrated Management Controller (IMC) Supervisor and Cisco UCS Director could allow an authenticated, remote attacker to cause a denial of service (DoS) condition on an affected system. The vulnerability is due to insufficient restrictions on the size or total amount of resources allowed via the web inte
nvd
CVE-2015-6399P4MEDIUMCVSS 6.8v1.0.0.0v1.0.0.12015-12-15
CVE-2015-6399 [MEDIUM] CWE-399 CVE-2015-6399: The Supervisor 1.0.0.0 and 1.0.0.1 in Cisco Integrated Management Controller (IMC) before 2.0(9) all The Supervisor 1.0.0.0 and 1.0.0.1 in Cisco Integrated Management Controller (IMC) before 2.0(9) allows remote authenticated users to cause a denial of service (IP interface outage) via crafted parameters in an HTTP request, aka Bug ID CSCuv38286.
nvd
CVE-2017-6617P4MEDIUMCVSS 5.4v3.0\(1c\)2017-04-20
CVE-2017-6617 [MEDIUM] CWE-287 CVE-2017-6617: A vulnerability in the session identification management functionality of the web-based GUI of Cisco A vulnerability in the session identification management functionality of the web-based GUI of Cisco Integrated Management Controller (IMC) 3.0(1c) could allow an unauthenticated, remote attacker to hijack a valid user session on an affected system. The vulnerability exists because the affected software does not assign a new session identifier to a us
nvd
CVE-2017-6618P4MEDIUMCVSS 5.4v3.0\(1c\)2017-04-20
CVE-2017-6618 [MEDIUM] CWE-79 CVE-2017-6618: A vulnerability in the web-based GUI of Cisco Integrated Management Controller (IMC) 3.0(1c) could a A vulnerability in the web-based GUI of Cisco Integrated Management Controller (IMC) 3.0(1c) could allow an authenticated, remote attacker to perform a cross-site scripting (XSS) attack. The vulnerability is due to insufficient validation of user-supplied input by the affected software. An attacker could exploit this vulnerability by persuading an auth
nvd
CVE-2020-3329P4MEDIUMCVSS 4.3≥ 1.1.0.0, < 2.2.1.32020-05-06
CVE-2020-3329 [MEDIUM] CWE-284 CVE-2020-3329: A vulnerability in role-based access control of Cisco Integrated Management Controller (IMC) Supervi A vulnerability in role-based access control of Cisco Integrated Management Controller (IMC) Supervisor, Cisco UCS Director, and Cisco UCS Director Express for Big Data could allow a read-only authenticated, remote attacker to disable user accounts on an affected system. The vulnerability is due to incorrect allocation of the enable/disable action but
nvd
CVE-2018-0149P4MEDIUMCVSS 4.8v2.1\(0.2\)v2.2\(0.2\)2018-06-07
CVE-2018-0149 [MEDIUM] CWE-79 CVE-2018-0149: A vulnerability in the web-based management interface of Cisco Integrated Management Controller Supe A vulnerability in the web-based management interface of Cisco Integrated Management Controller Supervisor Software and Cisco UCS Director Software could allow an authenticated, remote attacker to conduct a Document Object Model-based (DOM-based), stored cross-site scripting (XSS) attack against a user of the web-based management interface of an affect
nvd
Cisco Integrated Management Controller Supervisor vulnerabilities | cvebase