Cisco Unified Computing System vulnerabilities
75 known vulnerabilities affecting cisco/unified_computing_system.
Total CVEs
75
CISA KEV
1
actively exploited
Public exploits
1
Exploited in wild
1
Severity breakdown
CRITICAL2HIGH34MEDIUM39
Vulnerabilities
Page 3 of 4
CVE-2015-4279P4HIGHCVSS 7.2v2.2\(3b\)2015-07-20
CVE-2015-4279 [HIGH] CWE-78 CVE-2015-4279: The Manager component in Cisco Unified Computing System (UCS) 2.2(3b) on B Blade Server devices allo
The Manager component in Cisco Unified Computing System (UCS) 2.2(3b) on B Blade Server devices allows local users to gain privileges for executing arbitrary CLI commands by leveraging access to the subordinate fabric interconnect, aka Bug ID CSCut32778.
nvd
CVE-2017-12334P4MEDIUMCVSS 6.7v7.0\(0\)hsk\(0.357\)2017-11-30
CVE-2017-12334 [MEDIUM] CWE-20 CVE-2017-12334: A vulnerability in the CLI of Cisco NX-OS System Software could allow an authenticated, local attack
A vulnerability in the CLI of Cisco NX-OS System Software could allow an authenticated, local attacker to perform a command injection attack. An attacker would need valid administrator credentials to perform this exploit. The vulnerability is due to insufficient input validation of command arguments. An attacker could exploit this vulnerability by in
nvd
CVE-2019-1879P4MEDIUMCVSS 6.7v4.0\(1c\)hs32019-06-20
CVE-2019-1879 [MEDIUM] CWE-78 CVE-2019-1879: A vulnerability in the CLI of Cisco Integrated Management Controller (IMC) could allow an authentica
A vulnerability in the CLI of Cisco Integrated Management Controller (IMC) could allow an authenticated, local attacker to inject arbitrary commands that are executed with root privileges. The vulnerability is due to insufficient validation of user-supplied input at the CLI. An attacker could exploit this vulnerability by authenticating with the admini
nvd
CVE-2015-6415P4HIGHCVSS 7.1v2.2\(3f\)a2015-12-12
CVE-2015-6415 [HIGH] CWE-399 CVE-2015-6415: Cisco Unified Computing System (UCS) 2.2(3f)A on Fabric Interconnect 6200 devices allows remote atta
Cisco Unified Computing System (UCS) 2.2(3f)A on Fabric Interconnect 6200 devices allows remote attackers to cause a denial of service (CPU consumption or device outage) via a SYN flood on the SSH port during the booting process, aka Bug ID CSCuu81757.
nvd
CVE-2017-6601P4HIGHCVSS 7.1v3.1\(1k\)a2017-04-07
CVE-2017-6601 [HIGH] CWE-78 CVE-2017-6601: A vulnerability in the CLI of the Cisco Unified Computing System (UCS) Manager, Cisco Firepower 4100
A vulnerability in the CLI of the Cisco Unified Computing System (UCS) Manager, Cisco Firepower 4100 Series Next-Generation Firewall (NGFW), and Cisco Firepower 9300 Security Appliance could allow an authenticated, local attacker to perform a command injection attack. More Information: CSCvb61384 CSCvb86764. Known Affected Releases: 2.0(1.68) 3.1(1k)A. K
nvd
CVE-2019-1631P4MEDIUMCVSS 5.3v4.0\(1c\)hs32019-06-20
CVE-2019-1631 [MEDIUM] CWE-306 CVE-2019-1631: A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC
A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) could allow an unauthenticated, remote attacker to access potentially sensitive system usage information. The vulnerability is due to a lack of proper data protection mechanisms. An attacker could exploit this vulnerability by sending a crafted HTTP r
nvd
CVE-2020-26062P4MEDIUMCVSS 5.3v3.2\(1d\)v3.2\(2b\)+40 more2024-11-18
CVE-2020-26062 [MEDIUM] CWE-203 CVE-2020-26062: A vulnerability in Cisco Integrated Management Controller could allow an unauthenticated, remot
A vulnerability in Cisco Integrated Management Controller could allow an unauthenticated, remote attacker to enumerate valid usernames within the vulnerable application.
The vulnerability is due to differences in authentication responses sent back from the application as part of an authentication attempt. An attacker could exploit this vulnerability
nvd
CVE-2017-6598P4MEDIUMCVSS 6.7v3.1\(1k\)a2017-04-07
CVE-2017-6598 [MEDIUM] CWE-862 CVE-2017-6598: A vulnerability in the debug plug-in functionality of the Cisco Unified Computing System (UCS) Manag
A vulnerability in the debug plug-in functionality of the Cisco Unified Computing System (UCS) Manager, Cisco Firepower 4100 Series Next-Generation Firewall (NGFW), and Cisco Firepower 9300 Security Appliance could allow an authenticated, local attacker to execute arbitrary commands, aka Privilege Escalation. More Information: CSCvb86725 CSCvb86797. K
nvd
CVE-2015-4183P4HIGHCVSS 7.2v1.2\(1a\)2015-06-17
CVE-2015-4183 [HIGH] CWE-78 CVE-2015-4183: Cisco UCS Central Software 1.2(1a) allows local users to gain privileges for OS command execution vi
Cisco UCS Central Software 1.2(1a) allows local users to gain privileges for OS command execution via a crafted CLI parameter, aka Bug ID CSCut32795.
nvd
CVE-2026-20085P4MEDIUMCVSS 6.1v3.1\(1d\)v3.1\(2b\)+142 more2026-04-01
CVE-2026-20085 [MEDIUM] CWE-79 CVE-2026-20085: A vulnerability in the web-based management interface of Cisco IMC could allow an unauthenticated, r
A vulnerability in the web-based management interface of Cisco IMC could allow an unauthenticated, remote attacker to conduct a reflected XSS attack against a user of the interface.
This vulnerability is due to insufficient validation of user input. An attacker could exploit this vulnerability by persuading a user of an affected interface to click a
nvd
CVE-2021-1590P4MEDIUMCVSS 5.3fixed in 4.0\(4m\)≥ 4.1, < 4.1\(3d\)2021-08-25
CVE-2021-1590 [MEDIUM] CWE-787 CVE-2021-1590: A vulnerability in the implementation of the system login block-for command for Cisco NX-OS Software
A vulnerability in the implementation of the system login block-for command for Cisco NX-OS Software could allow an unauthenticated, remote attacker to cause a login process to unexpectedly restart, causing a denial of service (DoS) condition. This vulnerability is due to a logic error in the implementation of the system login block-for command when a
nvd
CVE-2015-0633P4MEDIUMCVSS 6.8v1.4v1.4\(1c\)+21 more2015-02-26
CVE-2015-0633 [MEDIUM] CWE-20 CVE-2015-0633: The Integrated Management Controller (IMC) in Cisco Unified Computing System (UCS) 1.4(7h) and earli
The Integrated Management Controller (IMC) in Cisco Unified Computing System (UCS) 1.4(7h) and earlier on C-Series servers allows remote attackers to bypass intended access restrictions by sending crafted DHCP response packets on the local network, aka Bug ID CSCuf52876.
nvd
CVE-2017-12255P4MEDIUMCVSS 6.7v1.5\(1c\)2017-09-21
CVE-2017-12255 [MEDIUM] CWE-20 CVE-2017-12255: A vulnerability in the CLI of Cisco UCS Central Software could allow an authenticated, local attacke
A vulnerability in the CLI of Cisco UCS Central Software could allow an authenticated, local attacker to gain shell access. The vulnerability is due to insufficient input validation of commands entered in the CLI, aka a Restricted Shell Break Vulnerability. An attacker could exploit this vulnerability by entering a specific command with crafted argum
nvd
CVE-2017-12331P4MEDIUMCVSS 6.7v7.0\(0\)hsk\(0.357\)2017-11-30
CVE-2017-12331 [MEDIUM] CWE-347 CVE-2017-12331: A vulnerability in Cisco NX-OS System Software could allow an authenticated, local attacker to bypas
A vulnerability in Cisco NX-OS System Software could allow an authenticated, local attacker to bypass signature verification when loading a software patch. The vulnerability is due to insufficient NX-OS signature verification for software patches. An authenticated, local attacker could exploit this vulnerability to bypass signature verification and
nvd
CVE-2017-12333P4MEDIUMCVSS 6.7v7.0\(0\)hsk\(0.357\)2017-11-30
CVE-2017-12333 [MEDIUM] CWE-347 CVE-2017-12333: A vulnerability in Cisco NX-OS System Software could allow an authenticated, local attacker to bypas
A vulnerability in Cisco NX-OS System Software could allow an authenticated, local attacker to bypass signature verification when loading a software image. The vulnerability is due to insufficient NX-OS signature verification for software images. An authenticated, local attacker could exploit this vulnerability to bypass signature verification and l
nvd
CVE-2019-1736P4MEDIUMCVSS 6.6v3.2\(3h\)c2020-09-23
CVE-2019-1736 [MEDIUM] CWE-347 CVE-2019-1736: A vulnerability in the firmware of the Cisco UCS C-Series Rack Servers could allow an authenticated,
A vulnerability in the firmware of the Cisco UCS C-Series Rack Servers could allow an authenticated, physical attacker to bypass Unified Extensible Firmware Interface (UEFI) Secure Boot validation checks and load a compromised software image on an affected device. The vulnerability is due to improper validation of the server firmware upgrade images. A
nvd
CVE-2017-6604P4MEDIUMCVSS 6.1v2.2\(8b\)v3.0\(1c\)+1 more2017-04-07
CVE-2017-6604 [MEDIUM] CWE-601 CVE-2017-6604: A vulnerability in the web interface of Cisco Integrated Management Controller (IMC) Software could
A vulnerability in the web interface of Cisco Integrated Management Controller (IMC) Software could allow an unauthenticated, remote attacker to redirect a user to a malicious web page. This vulnerability affects the following Cisco products running Cisco IMC Software: Unified Computing System (UCS) B-Series M3 and M4 Blade Servers, Unified Computing S
nvd
CVE-2019-1725P4MEDIUMCVSS 5.5fixed in 4.0\(2a\)2019-04-18
CVE-2019-1725 [MEDIUM] CWE-78 CVE-2019-1725: A vulnerability in the local management CLI implementation for specific commands on the Cisco UCS B-
A vulnerability in the local management CLI implementation for specific commands on the Cisco UCS B-Series Blade Servers could allow an authenticated, local attacker to overwrite an arbitrary file on disk. It is also possible the attacker could inject CLI command parameters that should not be allowed for a specific subset of local management CLI comman
nvd
CVE-2014-8003P4HIGHCVSS 7.2≤ 2.2\(2c\)a2014-12-10
CVE-2014-8003 [HIGH] CWE-20 CVE-2014-8003: Cisco Integrated Management Controller in Cisco Unified Computing System 2.2(2c)A and earlier allows
Cisco Integrated Management Controller in Cisco Unified Computing System 2.2(2c)A and earlier allows local users to obtain shell access via a crafted map-nfs command, aka Bug ID CSCup05998.
nvd
CVE-2017-12338P4MEDIUMCVSS 6.0v7.0\(0\)hsk\(0.357\)2017-11-30
CVE-2017-12338 [MEDIUM] CWE-20 CVE-2017-12338: A vulnerability in the CLI of Cisco NX-OS System Software could allow an authenticated, local attack
A vulnerability in the CLI of Cisco NX-OS System Software could allow an authenticated, local attacker to read the contents of arbitrary files. The vulnerability is due to insufficient input validation for a specific CLI command. An attacker could exploit this vulnerability by issuing a crafted command on the CLI. An exploit could allow the attacker
nvd