Vulnerabilities > Cisco > Unified Computing System > Low

DATE CVE VULNERABILITY TITLE RISK
2019-06-20 CVE-2019-1628 Integer Underflow (Wrap or Wraparound) vulnerability in Cisco products
A vulnerability in the web server of Cisco Integrated Management Controller (IMC) could allow an authenticated, local attacker to cause a buffer overflow, resulting in a denial of service (DoS) condition on an affected device.
local
low complexity
cisco CWE-191
2.1
2019-06-20 CVE-2019-1630 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Cisco products
A vulnerability in the firmware signature checking program of Cisco Integrated Management Controller (IMC) could allow an authenticated, local attacker to cause a buffer overflow, resulting in a denial of service (DoS) condition.
local
low complexity
cisco CWE-119
2.1
2019-04-18 CVE-2019-1725 Improper Input Validation vulnerability in Cisco Unified Computing System 4.0(1B)A
A vulnerability in the local management CLI implementation for specific commands on the Cisco UCS B-Series Blade Servers could allow an authenticated, local attacker to overwrite an arbitrary file on disk.
local
low complexity
cisco CWE-20
3.6
2017-11-30 CVE-2017-12338 Improper Input Validation vulnerability in Cisco products
A vulnerability in the CLI of Cisco NX-OS System Software could allow an authenticated, local attacker to read the contents of arbitrary files.
local
low complexity
cisco CWE-20
2.1
2017-04-07 CVE-2017-6601 OS Command Injection vulnerability in Cisco products
A vulnerability in the CLI of the Cisco Unified Computing System (UCS) Manager, Cisco Firepower 4100 Series Next-Generation Firewall (NGFW), and Cisco Firepower 9300 Security Appliance could allow an authenticated, local attacker to perform a command injection attack.
local
low complexity
cisco CWE-78
3.6
2017-04-07 CVE-2017-6602 OS Command Injection vulnerability in Cisco products
A vulnerability in the CLI of Cisco Unified Computing System (UCS) Manager, Cisco Firepower 4100 Series Next-Generation Firewall (NGFW), and Cisco Firepower 9300 Security Appliance could allow an authenticated, local attacker to perform a command injection attack.
local
low complexity
cisco CWE-78
3.6