cbcvebase.

Cisco Unified Computing System vulnerabilities

75 known vulnerabilities affecting cisco/unified_computing_system.

Total CVEs
75
CISA KEV
1
actively exploited
Public exploits
1
Exploited in wild
1
Severity breakdown
CRITICAL2HIGH34MEDIUM39

Vulnerabilities

Page 4 of 4
CVE-2024-20294P4MEDIUMCVSS 6.6v3.1\(1e\)v3.1\(1g\)+98 more2024-02-29
CVE-2024-20294 [MEDIUM] CWE-805 CVE-2024-20294: A vulnerability in the Link Layer Discovery Protocol (LLDP) feature of Cisco FXOS Software and Cisco A vulnerability in the Link Layer Discovery Protocol (LLDP) feature of Cisco FXOS Software and Cisco NX-OS Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper handling of specific fields in an LLDP frame. An attacker could exploit this vu
nvd
CVE-2026-20089P4MEDIUMCVSS 4.8v3.1\(1d\)v3.1\(2b\)+148 more2026-04-01
CVE-2026-20089 [MEDIUM] CWE-79 CVE-2026-20089: A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, rem A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with administrative privileges to conduct a stored XSS attack against a user of the interface. This vulnerability is due to insufficient validation of user input. An attacker could exploit this vulnerability by persuading a user of an aff
nvd
CVE-2026-20090P4MEDIUMCVSS 4.8v3.1\(1d\)v3.1\(2b\)+148 more2026-04-01
CVE-2026-20090 [MEDIUM] CWE-79 CVE-2026-20090: A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, rem A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with administrative privileges to conduct a stored XSS attack against a user of the interface. This vulnerability is due to insufficient validation of user input. An attacker could exploit this vulnerability by persuading a user of an aff
nvd
CVE-2026-20088P4MEDIUMCVSS 4.8v3.1\(1d\)v3.1\(2b\)+142 more2026-04-01
CVE-2026-20088 [MEDIUM] CWE-79 CVE-2026-20088: A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, rem A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with administrative privileges to conduct a stored XSS attack against a user of the interface. This vulnerability is due to insufficient validation of user input. An attacker could exploit this vulnerability by persuading a user of an aff
nvd
CVE-2026-20087P4MEDIUMCVSS 4.8v3.1\(1d\)v3.1\(2b\)+148 more2026-04-01
CVE-2026-20087 [MEDIUM] CWE-79 CVE-2026-20087: A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, rem A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with administrative privileges to conduct a stored XSS attack against a user of the interface. This vulnerability is due to insufficient validation of user input. An attacker could exploit this vulnerability by persuading a user of an aff
nvd
CVE-2017-12332P4MEDIUMCVSS 4.4v7.0\(0\)hsk\(0.357\)2017-11-30
CVE-2017-12332 [MEDIUM] CWE-434 CVE-2017-12332: A vulnerability in Cisco NX-OS System Software patch installation could allow an authenticated, loca A vulnerability in Cisco NX-OS System Software patch installation could allow an authenticated, local attacker to write a file to arbitrary locations. The vulnerability is due to insufficient restrictions in the patch installation process. An attacker could exploit this vulnerability by installing a crafted patch image on an affected device. The vul
nvd
CVE-2015-6355P4MEDIUMCVSS 5.0v2.2\(5b\)a2015-11-04
CVE-2015-6355 [MEDIUM] CWE-200 CVE-2015-6355: The web interface in Cisco Unified Computing System (UCS) 2.2(5b)A on blade servers allows remote at The web interface in Cisco Unified Computing System (UCS) 2.2(5b)A on blade servers allows remote attackers to obtain potentially sensitive version information by visiting an unspecified URL, aka Bug ID CSCuw87226.
nvd
CVE-2019-1628P4MEDIUMCVSS 5.5v4.0\(1c\)hs32019-06-20
CVE-2019-1628 [MEDIUM] CWE-191 CVE-2019-1628: A vulnerability in the web server of Cisco Integrated Management Controller (IMC) could allow an aut A vulnerability in the web server of Cisco Integrated Management Controller (IMC) could allow an authenticated, local attacker to cause a buffer overflow, resulting in a denial of service (DoS) condition on an affected device. The vulnerability is due to incorrect bounds checking. An attacker could exploit this vulnerability by sending a crafted HTTP
nvd
CVE-2017-12336P4MEDIUMCVSS 4.2v7.0\(0\)hsk\(0.357\)2017-11-30
CVE-2017-12336 [MEDIUM] CWE-20 CVE-2017-12336: A vulnerability in the TCL scripting subsystem of Cisco NX-OS System Software could allow an authent A vulnerability in the TCL scripting subsystem of Cisco NX-OS System Software could allow an authenticated, local attacker to escape the interactive TCL shell and gain unauthorized access to the underlying operating system of the device. The vulnerability exists due to insufficient input validation of user-supplied files passed to the interactive TCL
nvd
CVE-2019-1630P4MEDIUMCVSS 5.5v4.0\(1c\)hs32019-06-20
CVE-2019-1630 [MEDIUM] CWE-119 CVE-2019-1630: A vulnerability in the firmware signature checking program of Cisco Integrated Management Controller A vulnerability in the firmware signature checking program of Cisco Integrated Management Controller (IMC) could allow an authenticated, local attacker to cause a buffer overflow, resulting in a denial of service (DoS) condition. The vulnerability is due to insufficient checking of an input buffer. An attacker could exploit this vulnerability by passi
nvd
CVE-2021-1592P4MEDIUMCVSS 4.3≥ 4.0, < 4.0\(4m\)≥ 4.1, < 4.1\(3e\)2021-08-25
CVE-2021-1592 [MEDIUM] CWE-664 CVE-2021-1592: A vulnerability in the way Cisco UCS Manager software handles SSH sessions could allow an authentica A vulnerability in the way Cisco UCS Manager software handles SSH sessions could allow an authenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper resource management for established SSH sessions. An attacker could exploit this vulnerability by opening a significant number
nvd
CVE-2014-8009P4MEDIUMCVSS 5.0≤ 2.1\(3f\)2014-12-10
CVE-2014-8009 [MEDIUM] CWE-200 CVE-2014-8009: The Management subsystem in Cisco Unified Computing System 2.1(3f) and earlier allows remote attacke The Management subsystem in Cisco Unified Computing System 2.1(3f) and earlier allows remote attackers to obtain sensitive information by reading log files, aka Bug ID CSCur99239.
nvd
CVE-2015-4259P4MEDIUMCVSS 4.3v1.5\(3\)v1.6\(0.16\)2015-07-10
CVE-2015-4259 [MEDIUM] CWE-310 CVE-2015-4259: The Integrated Management Controller on Cisco Unified Computing System (UCS) C servers with software The Integrated Management Controller on Cisco Unified Computing System (UCS) C servers with software 1.5(3) and 1.6(0.16) has a default SSL certificate, which makes it easier for man-in-the-middle attackers to bypass cryptographic protection mechanisms by leveraging knowledge of a private key, aka Bug IDs CSCum56133 and CSCum56177.
nvd
CVE-2017-6602P4MEDIUMCVSS 4.4v3.1\(1k\)a2017-04-07
CVE-2017-6602 [MEDIUM] CWE-78 CVE-2017-6602: A vulnerability in the CLI of Cisco Unified Computing System (UCS) Manager, Cisco Firepower 4100 Ser A vulnerability in the CLI of Cisco Unified Computing System (UCS) Manager, Cisco Firepower 4100 Series Next-Generation Firewall (NGFW), and Cisco Firepower 9300 Security Appliance could allow an authenticated, local attacker to perform a command injection attack. More Information: CSCvb66189 CSCvb86775. Known Affected Releases: 2.0(1.68) 3.1(1k)A. Kno
nvd
CVE-2012-4081P4MEDIUMCVSS 4.6v1.0\(2k\)v1.0_base+15 more2013-09-20
CVE-2012-4081 [MEDIUM] CWE-119 CVE-2012-4081: MCServer in the Cisco Management Controller in Cisco Unified Computing System (UCS) allows local use MCServer in the Cisco Management Controller in Cisco Unified Computing System (UCS) allows local users to cause a denial of service (application crash) via invalid MCTools parameters, aka Bug ID CSCtg20734.
nvd