Vulnerabilities > Cisco > Unified Computing System

DATE CVE VULNERABILITY TITLE RISK
2019-04-18 CVE-2019-1725 OS Command Injection vulnerability in Cisco Unified Computing System
A vulnerability in the local management CLI implementation for specific commands on the Cisco UCS B-Series Blade Servers could allow an authenticated, local attacker to overwrite an arbitrary file on disk.
local
low complexity
cisco CWE-78
5.5
2018-10-05 CVE-2018-0431 Command Injection vulnerability in Cisco Unified Computing System 2.0Base/3.0(3A)/3.1(3)
A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) Software could allow an authenticated, remote attacker to inject and execute arbitrary commands with root privileges on an affected device.
network
low complexity
cisco CWE-77
8.8
2018-10-05 CVE-2018-0430 Command Injection vulnerability in Cisco Unified Computing System 2.0Base/3.0(3A)/3.1(3)
A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) Software could allow an authenticated, remote attacker to inject and execute arbitrary commands with root privileges on an affected device.
network
low complexity
cisco CWE-77
8.8
2018-06-07 CVE-2018-0338 Incorrect Authorization vulnerability in Cisco Unified Computing System
A vulnerability in the role-based access-checking mechanisms of Cisco Unified Computing System (UCS) Software could allow an authenticated, local attacker to execute arbitrary commands on an affected system.
local
low complexity
cisco CWE-863
7.8
2017-11-30 CVE-2017-12341 Command Injection vulnerability in Cisco Nx-Os and Unified Computing System
A vulnerability in the CLI of Cisco NX-OS System Software could allow an authenticated, local attacker to perform a command injection attack.
local
low complexity
cisco CWE-77
6.7
2017-11-30 CVE-2017-12338 Improper Input Validation vulnerability in Cisco products
A vulnerability in the CLI of Cisco NX-OS System Software could allow an authenticated, local attacker to read the contents of arbitrary files.
local
low complexity
cisco CWE-20
6.0
2017-11-30 CVE-2017-12336 Improper Input Validation vulnerability in Cisco Nx-Os and Unified Computing System
A vulnerability in the TCL scripting subsystem of Cisco NX-OS System Software could allow an authenticated, local attacker to escape the interactive TCL shell and gain unauthorized access to the underlying operating system of the device.
local
low complexity
cisco CWE-20
4.2
2017-11-30 CVE-2017-12335 Command Injection vulnerability in Cisco Nx-Os and Unified Computing System
A vulnerability in the CLI of Cisco NX-OS System Software could allow an authenticated, local attacker to perform a command injection attack.
local
low complexity
cisco CWE-77
6.3
2017-11-30 CVE-2017-12334 Improper Input Validation vulnerability in Cisco Nx-Os and Unified Computing System
A vulnerability in the CLI of Cisco NX-OS System Software could allow an authenticated, local attacker to perform a command injection attack.
local
low complexity
cisco CWE-20
6.7
2017-11-30 CVE-2017-12333 Improper Verification of Cryptographic Signature vulnerability in Cisco Nx-Os and Unified Computing System
A vulnerability in Cisco NX-OS System Software could allow an authenticated, local attacker to bypass signature verification when loading a software image.
local
low complexity
cisco CWE-347
6.7