Lucene search

K
ciscoCiscoCISCO-SA-20151102-UCS
HistoryNov 02, 2015 - 10:00 a.m.

Cisco Unified Computing System Blade Server Information Disclosure Vulnerability

2015-11-0210:00:00
tools.cisco.com
24

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

EPSS

0.002

Percentile

52.8%

A vulnerability in the web interface of the Cisco Unified Computing System (UCS) Blade Server could allow an unauthenticated, remote attacker to obtain information about the UCS software version.

The vulnerability is due to the verbose output that is returned when a specific URL is submitted to an affected system. An attacker could exploit this vulnerability by browsing to a specific URL. A successful exploit could allow an attacker to obtain information from the UCS. The information could be used for reconnaissance attacks.

Cisco has not released software updates that address this vulnerability. There are no workarounds that mitigate this vulnerability.

This advisory is available at the following link: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20151102-ucs[“https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20151102-ucs”]

Affected configurations

Vulners
Node
ciscounified_computing_systemMatchany
OR
ciscounified_computing_systemMatchany
VendorProductVersionCPE
ciscounified_computing_systemanycpe:2.3:h:cisco:unified_computing_system:any:*:*:*:*:*:*:*

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

EPSS

0.002

Percentile

52.8%

Related for CISCO-SA-20151102-UCS