Vulnerabilities > Cisco > UCS Director > 6.0.0.1

DATE CVE VULNERABILITY TITLE RISK
2022-05-27 CVE-2022-20765 Cross-site Scripting vulnerability in Cisco UCS Director
A vulnerability in the web applications of Cisco UCS Director could allow an authenticated, remote attacker to conduct a cross-site scripting attack on an affected system.
network
low complexity
cisco CWE-79
4.8
2021-12-10 CVE-2021-44228 Deserialization of Untrusted Data vulnerability in multiple products
Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints.
10.0
2020-08-17 CVE-2020-3464 Cross-site Scripting vulnerability in Cisco UCS Director
A vulnerability in the web-based management interface of Cisco UCS Director could allow an authenticated, remote attacker with administrative credentials to conduct a cross-site scripting (XSS) attack against a user of the interface.
network
low complexity
cisco CWE-79
4.8
2020-06-18 CVE-2020-3242 Information Exposure vulnerability in Cisco UCS Director
A vulnerability in the REST API of Cisco UCS Director could allow an authenticated, remote attacker with administrative privileges to obtain confidential information from an affected device.
network
low complexity
cisco CWE-200
4.0
2020-06-18 CVE-2020-3241 Path Traversal vulnerability in Cisco UCS Director
A vulnerability in the orchestration tasks of Cisco UCS Director could allow an authenticated, remote attacker to perform a path traversal attack on an affected device.
network
low complexity
cisco CWE-22
8.5
2020-05-06 CVE-2020-3329 Unspecified vulnerability in Cisco products
A vulnerability in role-based access control of Cisco Integrated Management Controller (IMC) Supervisor, Cisco UCS Director, and Cisco UCS Director Express for Big Data could allow a read-only authenticated, remote attacker to disable user accounts on an affected system.
network
low complexity
cisco
4.0
2020-04-15 CVE-2020-3252 Path Traversal vulnerability in Cisco UCS Director and UCS Director Express FOR BIG Data
Multiple vulnerabilities in the REST API of Cisco UCS Director and Cisco UCS Director Express for Big Data may allow a remote attacker to bypass authentication or conduct directory traversal attacks on an affected device.
network
low complexity
cisco CWE-22
4.0
2020-04-15 CVE-2020-3251 Path Traversal vulnerability in Cisco UCS Director and UCS Director Express FOR BIG Data
Multiple vulnerabilities in the REST API of Cisco UCS Director and Cisco UCS Director Express for Big Data may allow a remote attacker to bypass authentication or conduct directory traversal attacks on an affected device.
network
low complexity
cisco CWE-22
critical
9.0
2020-04-15 CVE-2020-3250 Improper Privilege Management vulnerability in Cisco UCS Director and UCS Director Express FOR BIG Data
Multiple vulnerabilities in the REST API of Cisco UCS Director and Cisco UCS Director Express for Big Data may allow a remote attacker to bypass authentication or conduct directory traversal attacks on an affected device.
network
low complexity
cisco CWE-269
7.5
2020-04-15 CVE-2020-3249 Path Traversal vulnerability in Cisco UCS Director and UCS Director Express FOR BIG Data
Multiple vulnerabilities in the REST API of Cisco UCS Director and Cisco UCS Director Express for Big Data may allow a remote attacker to bypass authentication or conduct directory traversal attacks on an affected device.
network
low complexity
cisco CWE-22
7.8