Cisco Unified Computing System vulnerabilities
64 known vulnerabilities affecting cisco/unified_computing_system.
Total CVEs
64
CISA KEV
1
actively exploited
Public exploits
1
Exploited in wild
1
Severity breakdown
CRITICAL2HIGH32MEDIUM30
Vulnerabilities
Page 2 of 4
CVE-2019-1883P3HIGHCVSS 7.8v4.0\(1c\)hs32019-08-21
CVE-2019-1883 [HIGH] CWE-78 CVE-2019-1883: A vulnerability in the command-line interface of Cisco Integrated Management Controller (IMC) could
A vulnerability in the command-line interface of Cisco Integrated Management Controller (IMC) could allow an authenticated, local attacker with read-only credentials to inject arbitrary commands that could allow them to obtain root privileges. The vulnerability is due to insufficient validation of user-supplied input on the command-line interface. An atta
nvd
CVE-2018-0338P3HIGHCVSS 7.8v5.5\(203\)v7.0\(0\)bz\(0.46\)+3 more2018-06-07
CVE-2018-0338 [HIGH] CWE-20 CVE-2018-0338: A vulnerability in the role-based access-checking mechanisms of Cisco Unified Computing System (UCS)
A vulnerability in the role-based access-checking mechanisms of Cisco Unified Computing System (UCS) Software could allow an authenticated, local attacker to execute arbitrary commands on an affected system. The vulnerability exists because the affected software lacks proper input and validation checks for certain file systems. An attacker could exploit
nvd
CVE-2019-1966P3HIGHCVSS 7.8v3.2\(3b\)av4.0\(1a\)a2019-08-30
CVE-2019-1966 [HIGH] CWE-264 CVE-2019-1966: A vulnerability in a specific CLI command within the local management (local-mgmt) context for Cisco
A vulnerability in a specific CLI command within the local management (local-mgmt) context for Cisco UCS Fabric Interconnect Software could allow an authenticated, local attacker to gain elevated privileges as the root user on an affected device. The vulnerability is due to extraneous subcommand options present for a specific CLI command within the loca
nvd
CVE-2015-0718P3HIGHCVSS 7.5v1.4_1iv1.4_1j+57 more2016-03-03
CVE-2015-0718 [HIGH] CWE-399 CVE-2015-0718: Cisco NX-OS 4.0 through 6.1 on Nexus 1000V 3000, 4000, 5000, 6000, and 7000 devices and Unified Comp
Cisco NX-OS 4.0 through 6.1 on Nexus 1000V 3000, 4000, 5000, 6000, and 7000 devices and Unified Computing System (UCS) platforms allows remote attackers to cause a denial of service (TCP stack reload) by sending crafted TCP packets to a device that has a TIME_WAIT TCP session, aka Bug ID CSCub70579.
nvd
CVE-2017-6633P3HIGHCVSS 7.5v3.0\(0.234\)2017-05-22
CVE-2017-6633 [HIGH] CWE-119 CVE-2017-6633: A vulnerability in the TCP throttling process of Cisco UCS C-Series Rack Servers 3.0(0.234) could al
A vulnerability in the TCP throttling process of Cisco UCS C-Series Rack Servers 3.0(0.234) could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to insufficient rate-limiting protection. An attacker could exploit this vulnerability by sending a high rate of TCP SYN p
nvd
CVE-2019-1632P3HIGHCVSS 8.0v4.0\(1c\)hs32019-06-20
CVE-2019-1632 [HIGH] CWE-352 CVE-2019-1632: A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC
A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) could allow an authenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack and perform arbitrary actions on an affected device. The vulnerability is due to insufficient CSRF protections for the web-based management interface of
nvd
CVE-2017-6597P3HIGHCVSS 7.8v3.1\(1k\)a2017-04-07
CVE-2017-6597 [HIGH] CWE-78 CVE-2017-6597: A vulnerability in the local-mgmt CLI command of the Cisco Unified Computing System (UCS) Manager, C
A vulnerability in the local-mgmt CLI command of the Cisco Unified Computing System (UCS) Manager, Cisco Firepower 4100 Series Next-Generation Firewall (NGFW), and Cisco Firepower 9300 Security Appliance could allow an authenticated, local attacker to perform a command injection attack. More Information: CSCvb61394 CSCvb86816. Known Affected Releases: 2.
nvd
CVE-2017-6600P3HIGHCVSS 7.8v3.1\(1k\)a2017-04-07
CVE-2017-6600 [HIGH] CWE-78 CVE-2017-6600: A vulnerability in the CLI of the Cisco Unified Computing System (UCS) Manager, Cisco Firepower 4100
A vulnerability in the CLI of the Cisco Unified Computing System (UCS) Manager, Cisco Firepower 4100 Series Next-Generation Firewall (NGFW), and Cisco Firepower 9300 Security Appliance could allow an authenticated, local attacker to perform a command injection attack. More Information: CSCvb61351 CSCvb61637. Known Affected Releases: 2.0(1.68) 3.1(1k)A. K
nvd
CVE-2016-6402P3HIGHCVSS 7.8v2.2\(1b\)v2.2\(1c\)+26 more2016-09-18
CVE-2016-6402 [HIGH] CWE-264 CVE-2016-6402: UCS Manager and UCS 6200 Fabric Interconnects in Cisco Unified Computing System (UCS) through 3.0(2d
UCS Manager and UCS 6200 Fabric Interconnects in Cisco Unified Computing System (UCS) through 3.0(2d) allow local users to obtain OS root access via crafted CLI input, aka Bug ID CSCuz91263.
nvd
CVE-2019-1627P3MEDIUMCVSS 6.5v4.0\(1c\)hs32019-06-20
CVE-2019-1627 [MEDIUM] CWE-78 CVE-2019-1627: A vulnerability in the Server Utilities of Cisco Integrated Management Controller (IMC) could allow
A vulnerability in the Server Utilities of Cisco Integrated Management Controller (IMC) could allow an authenticated, remote attacker to gain unauthorized access to sensitive user information from the configuration data that is stored on the affected system. The vulnerability is due to insufficient protection of data in the configuration file. An attack
nvd
CVE-2017-12335P3MEDIUMCVSS 6.3v7.0\(0\)hsk\(0.357\)2017-11-30
CVE-2017-12335 [MEDIUM] CWE-77 CVE-2017-12335: A vulnerability in the CLI of Cisco NX-OS System Software could allow an authenticated, local attack
A vulnerability in the CLI of Cisco NX-OS System Software could allow an authenticated, local attacker to perform a command injection attack. The vulnerability is due to insufficient input validation of command arguments. An attacker could exploit this vulnerability by injecting crafted command arguments into a vulnerable CLI command and gain unautho
nvd
CVE-2017-12341P3MEDIUMCVSS 6.7v7.0\(0\)hsk\(0.357\)2017-11-30
CVE-2017-12341 [MEDIUM] CWE-77 CVE-2017-12341: A vulnerability in the CLI of Cisco NX-OS System Software could allow an authenticated, local attack
A vulnerability in the CLI of Cisco NX-OS System Software could allow an authenticated, local attacker to perform a command injection attack. An attacker would need valid administrator credentials to perform this exploit. The vulnerability is due to insufficient input validation during the installation of a software patch. An attacker could exploit t
nvd
CVE-2017-12329P3MEDIUMCVSS 6.3v7.0\(0\)hsk\(0.357\)2017-11-30
CVE-2017-12329 [MEDIUM] CWE-77 CVE-2017-12329: A vulnerability in the CLI of Cisco Firepower Extensible Operating System (FXOS) and NX-OS System So
A vulnerability in the CLI of Cisco Firepower Extensible Operating System (FXOS) and NX-OS System Software could allow an authenticated, local attacker to perform a command injection attack. The vulnerability is due to insufficient input validation of command arguments to the CLI parser. An attacker could exploit this vulnerability by injecting craft
nvd
CVE-2019-1629P3MEDIUMCVSS 5.3v4.0\(1c\)hs32019-06-20
CVE-2019-1629 [MEDIUM] CWE-306 CVE-2019-1629: A vulnerability in the configuration import utility of Cisco Integrated Management Controller (IMC)
A vulnerability in the configuration import utility of Cisco Integrated Management Controller (IMC) could allow an unauthenticated, remote attacker to have write access and upload arbitrary data to the filesystem. The vulnerability is due to a failure to delete temporarily uploaded files. An attacker could exploit this vulnerability by crafting a malic
nvd
CVE-2015-4279P3HIGHCVSS 7.2v2.2\(3b\)2015-07-20
CVE-2015-4279 [HIGH] CWE-78 CVE-2015-4279: The Manager component in Cisco Unified Computing System (UCS) 2.2(3b) on B Blade Server devices allo
The Manager component in Cisco Unified Computing System (UCS) 2.2(3b) on B Blade Server devices allows local users to gain privileges for executing arbitrary CLI commands by leveraging access to the subordinate fabric interconnect, aka Bug ID CSCut32778.
nvd
CVE-2017-12334P4MEDIUMCVSS 6.7v7.0\(0\)hsk\(0.357\)2017-11-30
CVE-2017-12334 [MEDIUM] CWE-20 CVE-2017-12334: A vulnerability in the CLI of Cisco NX-OS System Software could allow an authenticated, local attack
A vulnerability in the CLI of Cisco NX-OS System Software could allow an authenticated, local attacker to perform a command injection attack. An attacker would need valid administrator credentials to perform this exploit. The vulnerability is due to insufficient input validation of command arguments. An attacker could exploit this vulnerability by in
nvd
CVE-2019-1879P4MEDIUMCVSS 6.7v4.0\(1c\)hs32019-06-20
CVE-2019-1879 [MEDIUM] CWE-78 CVE-2019-1879: A vulnerability in the CLI of Cisco Integrated Management Controller (IMC) could allow an authentica
A vulnerability in the CLI of Cisco Integrated Management Controller (IMC) could allow an authenticated, local attacker to inject arbitrary commands that are executed with root privileges. The vulnerability is due to insufficient validation of user-supplied input at the CLI. An attacker could exploit this vulnerability by authenticating with the admini
nvd
CVE-2015-6415P4HIGHCVSS 7.1v2.2\(3f\)a2015-12-12
CVE-2015-6415 [HIGH] CWE-399 CVE-2015-6415: Cisco Unified Computing System (UCS) 2.2(3f)A on Fabric Interconnect 6200 devices allows remote atta
Cisco Unified Computing System (UCS) 2.2(3f)A on Fabric Interconnect 6200 devices allows remote attackers to cause a denial of service (CPU consumption or device outage) via a SYN flood on the SSH port during the booting process, aka Bug ID CSCuu81757.
nvd
CVE-2017-6601P4HIGHCVSS 7.1v3.1\(1k\)a2017-04-07
CVE-2017-6601 [HIGH] CWE-78 CVE-2017-6601: A vulnerability in the CLI of the Cisco Unified Computing System (UCS) Manager, Cisco Firepower 4100
A vulnerability in the CLI of the Cisco Unified Computing System (UCS) Manager, Cisco Firepower 4100 Series Next-Generation Firewall (NGFW), and Cisco Firepower 9300 Security Appliance could allow an authenticated, local attacker to perform a command injection attack. More Information: CSCvb61384 CSCvb86764. Known Affected Releases: 2.0(1.68) 3.1(1k)A. K
nvd
CVE-2019-1631P4MEDIUMCVSS 5.3v4.0\(1c\)hs32019-06-20
CVE-2019-1631 [MEDIUM] CWE-306 CVE-2019-1631: A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC
A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) could allow an unauthenticated, remote attacker to access potentially sensitive system usage information. The vulnerability is due to a lack of proper data protection mechanisms. An attacker could exploit this vulnerability by sending a crafted HTTP r
nvd