Vulnerabilities > Cisco > Unified Computing System Director > Medium

DATE CVE VULNERABILITY TITLE RISK
2018-10-05 CVE-2018-15404 Allocation of Resources Without Limits or Throttling vulnerability in Cisco products
A vulnerability in the web interface of Cisco Integrated Management Controller (IMC) Supervisor and Cisco UCS Director could allow an authenticated, remote attacker to cause a denial of service (DoS) condition on an affected system.
network
low complexity
cisco CWE-770
6.5
2018-03-08 CVE-2018-0219 Cross-site Scripting vulnerability in Cisco Unified Computing System Director 6.6(0.0)
A vulnerability in the web-based management interface of Cisco Unified Computing System (UCS) Director could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of an affected device.
network
low complexity
cisco CWE-79
6.1
2017-04-07 CVE-2017-3817 Incorrect Authorization vulnerability in Cisco Unified Computing System Director 5.5.0.1/6.0.0.0
A vulnerability in the role-based resource checking functionality of Cisco Unified Computing System (UCS) Director could allow an authenticated, remote attacker to view unauthorized information for any virtual machine in a UCS domain.
network
low complexity
cisco CWE-863
4.3
2017-03-17 CVE-2017-3868 Cross-site Scripting vulnerability in Cisco Unified Computing System Director 6.0(0.0)
A vulnerability in the web-based management interface of Cisco UCS Director could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of an affected device.
network
low complexity
cisco CWE-79
6.1