Vulnerabilities > Cisco > Unified Computing System Central Software

DATE CVE VULNERABILITY TITLE RISK
2021-02-04 CVE-2021-1354 Improper Certificate Validation vulnerability in Cisco Unified Computing System Central Software
A vulnerability in the certificate registration process of Cisco Unified Computing System (UCS) Central Software could allow an authenticated, adjacent attacker to register a rogue Cisco Unified Computing System Manager (UCSM).
low complexity
cisco CWE-295
3.5
2018-02-08 CVE-2018-0113 Improper Input Validation vulnerability in Cisco Unified Computing System Central Software 1.5(1C)
A vulnerability in an operations script of Cisco UCS Central could allow an authenticated, remote attacker to execute arbitrary shell commands with the privileges of the daemon user.
network
low complexity
cisco CWE-20
8.8
2018-01-18 CVE-2018-0094 Resource Exhaustion vulnerability in Cisco Unified Computing System Central Software 1.4(1A)
A vulnerability in IPv6 ingress packet processing for Cisco UCS Central Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition due to high CPU utilization on the targeted device.
network
low complexity
cisco CWE-400
7.5
2017-11-30 CVE-2017-12349 Cross-site Scripting vulnerability in Cisco Unified Computing System Central Software 2.2(1A)A
Multiple vulnerabilities in the web-based management interface of Cisco UCS Central Software could allow a remote attacker to conduct a cross-site scripting (XSS) attack against a user of the affected interface or hijack a valid session ID from a user of the affected interface.
network
low complexity
cisco CWE-79
5.4
2017-11-30 CVE-2017-12348 Cross-site Scripting vulnerability in Cisco Unified Computing System Central Software 2.2(1A)A
Multiple vulnerabilities in the web-based management interface of Cisco UCS Central Software could allow a remote attacker to conduct a cross-site scripting (XSS) attack against a user of the affected interface or hijack a valid session ID from a user of the affected interface.
network
low complexity
cisco CWE-79
5.4
2016-05-21 CVE-2016-1401 Cross-site Scripting vulnerability in Cisco Unified Computing System Central Software 1.4(1A)
Cross-site scripting (XSS) vulnerability in the management interface in Cisco Unified Computing System (UCS) Central Software 1.4(1a) allows remote attackers to inject arbitrary web script or HTML via a crafted value, aka Bug ID CSCuy91250.
network
low complexity
cisco CWE-79
6.1
2016-04-14 CVE-2016-1352 OS Command Injection vulnerability in Cisco Unified Computing System Central Software 1.3(0.1)
Cisco Unified Computing System (UCS) Central Software 1.3(1b) and earlier allows remote attackers to execute arbitrary OS commands via a crafted HTTP request, aka Bug ID CSCuv33856.
network
low complexity
cisco CWE-78
critical
9.8