Vulnerabilities > Cisco > Integrated Management Controller Supervisor

DATE CVE VULNERABILITY TITLE RISK
2018-06-07 CVE-2018-0149 Cross-site Scripting vulnerability in Cisco Integrated Management Controller Supervisor 2.1(0.2)/2.2(0.2)
A vulnerability in the web-based management interface of Cisco Integrated Management Controller Supervisor Software and Cisco UCS Director Software could allow an authenticated, remote attacker to conduct a Document Object Model-based (DOM-based), stored cross-site scripting (XSS) attack against a user of the web-based management interface of an affected device.
network
cisco CWE-79
3.5
2017-04-20 CVE-2017-6619 Improper Input Validation vulnerability in Cisco Integrated Management Controller Supervisor 3.0(1C)
A vulnerability in the web-based GUI of Cisco Integrated Management Controller (IMC) 3.0(1c) could allow an authenticated, remote attacker to execute arbitrary commands on an affected system.
network
low complexity
cisco CWE-20
critical
9.0
2017-04-20 CVE-2017-6618 Cross-site Scripting vulnerability in Cisco Integrated Management Controller Supervisor 3.0(1C)
A vulnerability in the web-based GUI of Cisco Integrated Management Controller (IMC) 3.0(1c) could allow an authenticated, remote attacker to perform a cross-site scripting (XSS) attack.
network
cisco CWE-79
3.5
2017-04-20 CVE-2017-6617 Improper Authentication vulnerability in Cisco Integrated Management Controller Supervisor 3.0(1C)
A vulnerability in the session identification management functionality of the web-based GUI of Cisco Integrated Management Controller (IMC) 3.0(1c) could allow an unauthenticated, remote attacker to hijack a valid user session on an affected system.
network
cisco CWE-287
4.3
2017-04-20 CVE-2017-6616 Improper Input Validation vulnerability in Cisco Integrated Management Controller Supervisor 3.0(1C)
A vulnerability in the web-based GUI of Cisco Integrated Management Controller (IMC) 3.0(1c) could allow an authenticated, remote attacker to execute arbitrary code on an affected system.
network
low complexity
cisco CWE-20
critical
9.0
2015-12-15 CVE-2015-6399 Resource Management Errors vulnerability in Cisco Integrated Management Controller Supervisor 1.0.0.0/1.0.0.1
The Supervisor 1.0.0.0 and 1.0.0.1 in Cisco Integrated Management Controller (IMC) before 2.0(9) allows remote authenticated users to cause a denial of service (IP interface outage) via crafted parameters in an HTTP request, aka Bug ID CSCuv38286.
network
low complexity
cisco CWE-399
6.8
2015-09-04 CVE-2015-6259 Improper Input Validation vulnerability in Cisco products
The JavaServer Pages (JSP) component in Cisco Integrated Management Controller (IMC) Supervisor before 1.0.0.1 and UCS Director (formerly Cloupia Unified Infrastructure Controller) before 5.2.0.1 allows remote attackers to write to arbitrary files via crafted HTTP requests, aka Bug IDs CSCus36435 and CSCus62625.
network
low complexity
cisco CWE-20
critical
9.4