Cisco Unified Computing System vulnerabilities
64 known vulnerabilities affecting cisco/unified_computing_system.
Total CVEs
64
CISA KEV
1
actively exploited
Public exploits
1
Exploited in wild
1
Severity breakdown
CRITICAL2HIGH32MEDIUM30
Vulnerabilities
Page 3 of 4
CVE-2020-26062P4MEDIUMCVSS 5.3v3.2\(1d\)v3.2\(2b\)+40 more2024-11-18
CVE-2020-26062 [MEDIUM] CWE-203 CVE-2020-26062: A vulnerability in Cisco Integrated Management Controller could allow an unauthenticated, remot
A vulnerability in Cisco Integrated Management Controller could allow an unauthenticated, remote attacker to enumerate valid usernames within the vulnerable application.
The vulnerability is due to differences in authentication responses sent back from the application as part of an authentication attempt. An attacker could exploit this vulnerability
nvd
CVE-2017-6598P4MEDIUMCVSS 6.7v3.1\(1k\)a2017-04-07
CVE-2017-6598 [MEDIUM] CWE-862 CVE-2017-6598: A vulnerability in the debug plug-in functionality of the Cisco Unified Computing System (UCS) Manag
A vulnerability in the debug plug-in functionality of the Cisco Unified Computing System (UCS) Manager, Cisco Firepower 4100 Series Next-Generation Firewall (NGFW), and Cisco Firepower 9300 Security Appliance could allow an authenticated, local attacker to execute arbitrary commands, aka Privilege Escalation. More Information: CSCvb86725 CSCvb86797. K
nvd
CVE-2015-4183P4HIGHCVSS 7.2v1.2\(1a\)2015-06-17
CVE-2015-4183 [HIGH] CWE-78 CVE-2015-4183: Cisco UCS Central Software 1.2(1a) allows local users to gain privileges for OS command execution vi
Cisco UCS Central Software 1.2(1a) allows local users to gain privileges for OS command execution via a crafted CLI parameter, aka Bug ID CSCut32795.
nvd
CVE-2015-0633P4MEDIUMCVSS 6.8v1.4v1.4\(1c\)+21 more2015-02-26
CVE-2015-0633 [MEDIUM] CWE-20 CVE-2015-0633: The Integrated Management Controller (IMC) in Cisco Unified Computing System (UCS) 1.4(7h) and earli
The Integrated Management Controller (IMC) in Cisco Unified Computing System (UCS) 1.4(7h) and earlier on C-Series servers allows remote attackers to bypass intended access restrictions by sending crafted DHCP response packets on the local network, aka Bug ID CSCuf52876.
nvd
CVE-2021-1590P4MEDIUMCVSS 5.3fixed in 4.0\(4m\)≥ 4.1, < 4.1\(3d\)2021-08-25
CVE-2021-1590 [MEDIUM] CWE-787 CVE-2021-1590: A vulnerability in the implementation of the system login block-for command for Cisco NX-OS Software
A vulnerability in the implementation of the system login block-for command for Cisco NX-OS Software could allow an unauthenticated, remote attacker to cause a login process to unexpectedly restart, causing a denial of service (DoS) condition. This vulnerability is due to a logic error in the implementation of the system login block-for command when a
nvd
CVE-2017-12255P4MEDIUMCVSS 6.7v1.5\(1c\)2017-09-21
CVE-2017-12255 [MEDIUM] CWE-20 CVE-2017-12255: A vulnerability in the CLI of Cisco UCS Central Software could allow an authenticated, local attacke
A vulnerability in the CLI of Cisco UCS Central Software could allow an authenticated, local attacker to gain shell access. The vulnerability is due to insufficient input validation of commands entered in the CLI, aka a Restricted Shell Break Vulnerability. An attacker could exploit this vulnerability by entering a specific command with crafted argum
nvd
CVE-2017-12331P4MEDIUMCVSS 6.7v7.0\(0\)hsk\(0.357\)2017-11-30
CVE-2017-12331 [MEDIUM] CWE-347 CVE-2017-12331: A vulnerability in Cisco NX-OS System Software could allow an authenticated, local attacker to bypas
A vulnerability in Cisco NX-OS System Software could allow an authenticated, local attacker to bypass signature verification when loading a software patch. The vulnerability is due to insufficient NX-OS signature verification for software patches. An authenticated, local attacker could exploit this vulnerability to bypass signature verification and
nvd
CVE-2017-12333P4MEDIUMCVSS 6.7v7.0\(0\)hsk\(0.357\)2017-11-30
CVE-2017-12333 [MEDIUM] CWE-347 CVE-2017-12333: A vulnerability in Cisco NX-OS System Software could allow an authenticated, local attacker to bypas
A vulnerability in Cisco NX-OS System Software could allow an authenticated, local attacker to bypass signature verification when loading a software image. The vulnerability is due to insufficient NX-OS signature verification for software images. An authenticated, local attacker could exploit this vulnerability to bypass signature verification and l
nvd
CVE-2019-1736P4MEDIUMCVSS 6.6v3.2\(3h\)c2020-09-23
CVE-2019-1736 [MEDIUM] CWE-347 CVE-2019-1736: A vulnerability in the firmware of the Cisco UCS C-Series Rack Servers could allow an authenticated,
A vulnerability in the firmware of the Cisco UCS C-Series Rack Servers could allow an authenticated, physical attacker to bypass Unified Extensible Firmware Interface (UEFI) Secure Boot validation checks and load a compromised software image on an affected device. The vulnerability is due to improper validation of the server firmware upgrade images. A
nvd
CVE-2017-6604P4MEDIUMCVSS 6.1v2.2\(8b\)v3.0\(1c\)+1 more2017-04-07
CVE-2017-6604 [MEDIUM] CWE-601 CVE-2017-6604: A vulnerability in the web interface of Cisco Integrated Management Controller (IMC) Software could
A vulnerability in the web interface of Cisco Integrated Management Controller (IMC) Software could allow an unauthenticated, remote attacker to redirect a user to a malicious web page. This vulnerability affects the following Cisco products running Cisco IMC Software: Unified Computing System (UCS) B-Series M3 and M4 Blade Servers, Unified Computing S
nvd
CVE-2019-1725P4MEDIUMCVSS 5.5fixed in 4.0\(2a\)2019-04-18
CVE-2019-1725 [MEDIUM] CWE-78 CVE-2019-1725: A vulnerability in the local management CLI implementation for specific commands on the Cisco UCS B-
A vulnerability in the local management CLI implementation for specific commands on the Cisco UCS B-Series Blade Servers could allow an authenticated, local attacker to overwrite an arbitrary file on disk. It is also possible the attacker could inject CLI command parameters that should not be allowed for a specific subset of local management CLI comman
nvd
CVE-2014-8003P4HIGHCVSS 7.2≤ 2.2\(2c\)a2014-12-10
CVE-2014-8003 [HIGH] CWE-20 CVE-2014-8003: Cisco Integrated Management Controller in Cisco Unified Computing System 2.2(2c)A and earlier allows
Cisco Integrated Management Controller in Cisco Unified Computing System 2.2(2c)A and earlier allows local users to obtain shell access via a crafted map-nfs command, aka Bug ID CSCup05998.
nvd
CVE-2017-12338P4MEDIUMCVSS 6.0v7.0\(0\)hsk\(0.357\)2017-11-30
CVE-2017-12338 [MEDIUM] CWE-20 CVE-2017-12338: A vulnerability in the CLI of Cisco NX-OS System Software could allow an authenticated, local attack
A vulnerability in the CLI of Cisco NX-OS System Software could allow an authenticated, local attacker to read the contents of arbitrary files. The vulnerability is due to insufficient input validation for a specific CLI command. An attacker could exploit this vulnerability by issuing a crafted command on the CLI. An exploit could allow the attacker
nvd
CVE-2024-20294P4MEDIUMCVSS 6.6v3.1\(1e\)v3.1\(1g\)+98 more2024-02-29
CVE-2024-20294 [MEDIUM] CWE-805 CVE-2024-20294: A vulnerability in the Link Layer Discovery Protocol (LLDP) feature of Cisco FXOS Software and Cisco
A vulnerability in the Link Layer Discovery Protocol (LLDP) feature of Cisco FXOS Software and Cisco NX-OS Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on an affected device.
This vulnerability is due to improper handling of specific fields in an LLDP frame. An attacker could exploit this vu
nvd
CVE-2017-12332P4MEDIUMCVSS 4.4v7.0\(0\)hsk\(0.357\)2017-11-30
CVE-2017-12332 [MEDIUM] CWE-434 CVE-2017-12332: A vulnerability in Cisco NX-OS System Software patch installation could allow an authenticated, loca
A vulnerability in Cisco NX-OS System Software patch installation could allow an authenticated, local attacker to write a file to arbitrary locations. The vulnerability is due to insufficient restrictions in the patch installation process. An attacker could exploit this vulnerability by installing a crafted patch image on an affected device. The vul
nvd
CVE-2015-6355P4MEDIUMCVSS 5.0v2.2\(5b\)a2015-11-04
CVE-2015-6355 [MEDIUM] CWE-200 CVE-2015-6355: The web interface in Cisco Unified Computing System (UCS) 2.2(5b)A on blade servers allows remote at
The web interface in Cisco Unified Computing System (UCS) 2.2(5b)A on blade servers allows remote attackers to obtain potentially sensitive version information by visiting an unspecified URL, aka Bug ID CSCuw87226.
nvd
CVE-2019-1628P4MEDIUMCVSS 5.5v4.0\(1c\)hs32019-06-20
CVE-2019-1628 [MEDIUM] CWE-191 CVE-2019-1628: A vulnerability in the web server of Cisco Integrated Management Controller (IMC) could allow an aut
A vulnerability in the web server of Cisco Integrated Management Controller (IMC) could allow an authenticated, local attacker to cause a buffer overflow, resulting in a denial of service (DoS) condition on an affected device. The vulnerability is due to incorrect bounds checking. An attacker could exploit this vulnerability by sending a crafted HTTP
nvd
CVE-2019-1630P4MEDIUMCVSS 5.5v4.0\(1c\)hs32019-06-20
CVE-2019-1630 [MEDIUM] CWE-119 CVE-2019-1630: A vulnerability in the firmware signature checking program of Cisco Integrated Management Controller
A vulnerability in the firmware signature checking program of Cisco Integrated Management Controller (IMC) could allow an authenticated, local attacker to cause a buffer overflow, resulting in a denial of service (DoS) condition. The vulnerability is due to insufficient checking of an input buffer. An attacker could exploit this vulnerability by passi
nvd
CVE-2017-12336P4MEDIUMCVSS 4.2v7.0\(0\)hsk\(0.357\)2017-11-30
CVE-2017-12336 [MEDIUM] CWE-20 CVE-2017-12336: A vulnerability in the TCL scripting subsystem of Cisco NX-OS System Software could allow an authent
A vulnerability in the TCL scripting subsystem of Cisco NX-OS System Software could allow an authenticated, local attacker to escape the interactive TCL shell and gain unauthorized access to the underlying operating system of the device. The vulnerability exists due to insufficient input validation of user-supplied files passed to the interactive TCL
nvd
CVE-2014-8009P4MEDIUMCVSS 5.0≤ 2.1\(3f\)2014-12-10
CVE-2014-8009 [MEDIUM] CWE-200 CVE-2014-8009: The Management subsystem in Cisco Unified Computing System 2.1(3f) and earlier allows remote attacke
The Management subsystem in Cisco Unified Computing System 2.1(3f) and earlier allows remote attackers to obtain sensitive information by reading log files, aka Bug ID CSCur99239.
nvd