Vulnerabilities > Cisco > Unified Computing System Central Software

DATE CVE VULNERABILITY TITLE RISK
2021-02-04 CVE-2021-1354 Improper Certificate Validation vulnerability in Cisco Unified Computing System Central Software
A vulnerability in the certificate registration process of Cisco Unified Computing System (UCS) Central Software could allow an authenticated, adjacent attacker to register a rogue Cisco Unified Computing System Manager (UCSM).
low complexity
cisco CWE-295
3.5
2018-02-08 CVE-2018-0113 Improper Input Validation vulnerability in Cisco Unified Computing System Central Software 1.5(1C)
A vulnerability in an operations script of Cisco UCS Central could allow an authenticated, remote attacker to execute arbitrary shell commands with the privileges of the daemon user.
network
low complexity
cisco CWE-20
6.5
2018-01-18 CVE-2018-0094 Resource Exhaustion vulnerability in Cisco Unified Computing System Central Software 1.4(1A)
A vulnerability in IPv6 ingress packet processing for Cisco UCS Central Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition due to high CPU utilization on the targeted device.
network
low complexity
cisco CWE-400
5.0
2017-11-30 CVE-2017-12349 Cross-site Scripting vulnerability in Cisco Unified Computing System Central Software 2.2(1A)A
Multiple vulnerabilities in the web-based management interface of Cisco UCS Central Software could allow a remote attacker to conduct a cross-site scripting (XSS) attack against a user of the affected interface or hijack a valid session ID from a user of the affected interface.
network
cisco CWE-79
3.5
2017-11-30 CVE-2017-12348 Cross-site Scripting vulnerability in Cisco Unified Computing System Central Software 2.2(1A)A
Multiple vulnerabilities in the web-based management interface of Cisco UCS Central Software could allow a remote attacker to conduct a cross-site scripting (XSS) attack against a user of the affected interface or hijack a valid session ID from a user of the affected interface.
network
cisco CWE-79
3.5
2016-05-21 CVE-2016-1401 Cross-site Scripting vulnerability in Cisco Unified Computing System Central Software 1.4(1A)
Cross-site scripting (XSS) vulnerability in the management interface in Cisco Unified Computing System (UCS) Central Software 1.4(1a) allows remote attackers to inject arbitrary web script or HTML via a crafted value, aka Bug ID CSCuy91250.
network
cisco CWE-79
4.3
2016-04-14 CVE-2016-1352 OS Command Injection vulnerability in Cisco Unified Computing System Central Software 1.3(0.1)
Cisco Unified Computing System (UCS) Central Software 1.3(1b) and earlier allows remote attackers to execute arbitrary OS commands via a crafted HTTP request, aka Bug ID CSCuv33856.
network
low complexity
cisco CWE-78
7.5
2015-12-05 CVE-2015-6388 Security Bypass vulnerability in Cisco Unified Computing System Central Software 1.3(0.1)
Cisco Unified Computing System (UCS) Central software 1.3(0.1) allows remote attackers to conduct server-side request forgery (SSRF) attacks via a crafted request, aka Bug ID CSCux33575.
network
low complexity
cisco
5.0
2015-12-05 CVE-2015-6387 Cross-site Scripting vulnerability in Cisco Unified Computing System Central Software 1.3(0.1)
Cross-site scripting (XSS) vulnerability in Cisco Unified Computing System (UCS) Central Software 1.3(0.1) allows remote attackers to inject arbitrary web script or HTML via a crafted value in a URL, aka Bug ID CSCux33573.
network
cisco CWE-79
4.3
2015-07-29 CVE-2015-4286 Improper Input Validation vulnerability in Cisco Unified Computing System Central Software 1.3(0.99)
The web framework in Cisco UCS Central Software 1.3(0.99) allows remote attackers to read arbitrary files via a crafted HTTP request, aka Bug ID CSCuu41377.
network
low complexity
cisco CWE-20
5.0