VendorsCiscounified_computing_systemall versions
Vulnerabilities

Cisco Unified Computing System

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

121CVEs
CVE-2012-4115
The fabric-interconnect component in Cisco Unified Computing System (UCS) does not encrypt KVM virtual-media data, which allows man-in-the-middle attackers to obtain sensitive information by sniffing the network or modify this traffic by inserting packets into the client-server data stream, aka Bug ID CSCtr72964.
Published 2013-10-21 · Modified
5.8EPSS 0.008
CVE-2012-4092
The management interface in the Central Software component in Cisco Unified Computing System (UCS) does not properly validate the identity of vCenter consoles, which allows man-in-the-middle attackers to read or modify an inter-device data stream by spoofing an identity, aka Bug ID CSCtk00683.
Published 2013-09-26 · Modified
5.8EPSS 0.008
CVE-2012-4073
The KVM subsystem in the client in Cisco Unified Computing System (UCS) does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers, and read or modify KVM data, via a crafted certificate, aka Bug ID CSCte90332.
Published 2013-09-20 · Modified
5.8EPSS 0.006
CVE-2012-4117
The fabric-interconnect component in Cisco Unified Computing System (UCS) does not properly verify X.509 certificates, which allows man-in-the-middle attackers to watch SSL KVM video-channel traffic or modify this traffic via a crafted certificate, aka Bug ID CSCtr73033.
Published 2013-10-19 · Modified
5.8EPSS 0.005
CVE-2019-1628
Cisco Integrated Management Controller Denial of Service Vulnerability
Published 2019-06-20 · Modified
5.5EPSS 0.004
CVE-2019-1725
Cisco UCS B-Series Blade Servers Local Management CLI Arbitrary File Creation or CLI Parameter Injection Vulnerability
Published 2019-04-18 · Modified
5.5EPSS 0.004
CVE-2019-1630
Cisco Integrated Management Controller Denial of Service Vulnerability
Published 2019-06-20 · Modified
5.5EPSS 0.003
CVE-2012-4095
The local file editor in the fabric-interconnect component in Cisco Unified Computing System (UCS) allows local users to gain privileges, and read or modify arbitrary files, via unspecified key bindings, aka Bug ID CSCtn04521.
Published 2013-10-02 · Modified
5.5EPSS 0.003
CVE-2012-4094
Buffer overflow in the Smart Call Home feature in the fabric interconnect in Cisco Unified Computing System (UCS) allows remote attackers to cause a denial of service by reading and forging control messages associated with Smart Call Home reports, aka Bug ID CSCtl00198.
Published 2013-09-24 · Modified
5.4EPSS 0.020
CVE-2020-10136
IP-in-IP protocol allows a remote, unauthenticated attacker to route arbitrary network traffic
Published 2020-06-02 · Modified
5.3EPSS 0.285
CVE-2019-1631
Cisco Integrated Management Controller Information Disclosure Vulnerability
Published 2019-06-20 · Modified
5.3EPSS 0.022
CVE-2019-1629
Cisco Integrated Management Controller Arbitrary File Write Vulnerability
Published 2019-06-20 · Modified
5.3EPSS 0.015
CVE-2021-1590
Cisco NX-OS Software system login block-for Denial of Service Vulnerability
Published 2021-08-25 · Modified
5.3EPSS 0.014
CVE-2020-26062
Cisco Integrated Management Controller Username Enumeration Vulnerability
Published 2024-11-18 · Analyzed
5.3EPSS 0.008
CVE-2012-4086
A setup script for fabric interconnect devices in Cisco Unified Computing System (UCS) allows remote attackers to execute arbitrary commands via invalid parameters, aka Bug ID CSCtg20790.
Published 2013-09-25 · Modified
5.1EPSS 0.029
CVE-2012-4087
A cluster setup script for fabric interconnect devices in Cisco Unified Computing System (UCS) allows remote attackers to execute arbitrary commands via invalid parameters, aka Bug ID CSCtg20793.
Published 2013-09-24 · Modified
5.1EPSS 0.019
CVE-2015-6355
The web interface in Cisco Unified Computing System (UCS) 2.2(5b)A on blade servers allows remote attackers to obtain potentially sensitive version information by visiting an unspecified URL, aka Bug ID CSCuw87226.
Published 2015-11-04 · Modified
5.0EPSS 0.017
CVE-2012-4085
The Intelligent Platform Management Interface (IPMI) implementation in the Blade Management Controller in Cisco Unified Computing System (UCS) allows remote attackers to enumerate valid usernames by observing IPMI interface responses, aka Bug ID CSCtg20761.
Published 2013-09-24 · Modified
5.0EPSS 0.017
CVE-2013-1190
The C-Series Rack Server component 1.4 in Cisco Unified Computing System (UCS) does not properly restrict inbound access to ports, which allows remote attackers to cause a denial of service (Integrated Management Controller reboot or hang) via crafted packets, as demonstrated by nmap, aka Bug ID CSCtx19850.
Published 2013-08-01 · Modified
5.0EPSS 0.015
CVE-2012-4079
The XML API service in the Fabric Interconnect component in Cisco Unified Computing System (UCS) allows remote attackers to cause a denial of service (API service outage) via a malformed XML document in a packet, aka Bug ID CSCtg48206.
Published 2013-09-26 · Modified
5.0EPSS 0.012
CVE-2014-8009
The Management subsystem in Cisco Unified Computing System 2.1(3f) and earlier allows remote attackers to obtain sensitive information by reading log files, aka Bug ID CSCur99239.
Published 2014-12-10 · Modified
5.0EPSS 0.012
CVE-2017-12332
A vulnerability in Cisco NX-OS System Software patch installation could allow an authenticated, local attacker to write a file to arbitrary locations. The vulnerability is due to insufficient restrictions in the patch installation process. An attacker could exploit this vulnerability by installing a crafted patch image on an affected device. The vulnerable operation occurs prior to patch activation. An exploit could allow the attacker to write arbitrary files on an affected system as root. The attacker would need valid administrator credentials to perform this exploit. This vulnerability affects the following products running Cisco NX-OS System Software: Multilayer Director Switches, Nexus 2000 Series Fabric Extenders, Nexus 5000 Series Switches, Nexus 5500 Platform Switches, Nexus 5600 Platform Switches, Nexus 6000 Series Switches, Nexus 7000 Series Switches, Nexus 7700 Series Switches, Unified Computing System Manager. Cisco Bug IDs: CSCvf16513, CSCvf23794, CSCvf23832.
Published 2017-11-30 · Modified
4.9EPSS 0.003
CVE-2026-20089
Cisco Integrated Management Controller Cross-Site Scripting Vulnerability
Published 2026-04-01 · Analyzed
4.8EPSS 0.002
CVE-2026-20090
Cisco Integrated Management Controller Cross-Site Scripting Vulnerability
Published 2026-04-01 · Analyzed
4.8EPSS 0.002
CVE-2026-20088
Cisco Integrated Management Controller Cross-Site Scripting Vulnerability
Published 2026-04-01 · Analyzed
4.8EPSS 0.002
CVE-2026-20087
Cisco Integrated Management Controller Cross-Site Scripting Vulnerability
Published 2026-04-01 · Analyzed
4.8EPSS 0.002
CVE-2017-12336
A vulnerability in the TCL scripting subsystem of Cisco NX-OS System Software could allow an authenticated, local attacker to escape the interactive TCL shell and gain unauthorized access to the underlying operating system of the device. The vulnerability exists due to insufficient input validation of user-supplied files passed to the interactive TCL shell of the affected device. An attacker could exploit this vulnerability to escape the scripting sandbox and execute arbitrary commands on the underlying operating system with the privileges of the authenticated user. To exploit this vulnerability, an attacker must have local access and be authenticated to the targeted device with administrative or tclsh execution privileges. This vulnerability affects the following products running Cisco NX-OS System Software: Multilayer Director Switches, Nexus 2000 Series Fabric Extenders, Nexus 3000 Series Switches, Nexus 3500 Platform Switches, Nexus 5000 Series Switches, Nexus 5500 Platform Switches, Nexus 5600 Platform Switches, Nexus 6000 Series Switches, Nexus 7000 Series Switches, Nexus 7700 Series Switches, Nexus 9000 Series Switches in standalone NX-OS mode, Nexus 9500 R-Series Line Cards and Fabric Modules, Unified Computing System Manager. Cisco Bug IDs: CSCve93750, CSCve93762, CSCve93763, CSCvg04127.
Published 2017-11-30 · Modified
4.6EPSS 0.004
CVE-2012-4105
The fabric-interconnect component in Cisco Unified Computing System (UCS) allows local users to cause a denial of service (component crash) via crafted "debug hardware" parameters, aka Bug ID CSCtq86468.
Published 2013-10-13 · Modified
4.6EPSS 0.003
CVE-2012-4081
MCServer in the Cisco Management Controller in Cisco Unified Computing System (UCS) allows local users to cause a denial of service (application crash) via invalid MCTools parameters, aka Bug ID CSCtg20734.
Published 2013-09-20 · Modified
4.6EPSS 0.003
CVE-2012-4113
The fabric-interconnect component in Cisco Unified Computing System (UCS) allows local users to gain privileges and read arbitrary files via crafted command parameters within the command-line interface, aka Bug ID CSCtr43374.
Published 2013-10-19 · Modified
4.6EPSS 0.003
CVE-2012-4107
The fabric-interconnect component in Cisco Unified Computing System (UCS) allows local users to gain privileges and execute arbitrary commands via crafted parameters to a file-related command, aka Bug ID CSCtq86489.
Published 2013-10-13 · Modified
4.6EPSS 0.003
CVE-2012-4093
The Manager component in Cisco Unified Computing System (UCS) allows local users to cause a denial of service via an invalid Smart Call Home contact address, aka Bug ID CSCtl00186.
Published 2013-09-20 · Modified
4.6EPSS 0.003
CVE-2013-5550
The fabric-interconnect component in Cisco Unified Computing System (UCS) allows local users to cause a denial of service via crafted command parameters that trigger hardware-component write operations, aka Bug ID CSCtq86549.
Published 2013-10-22 · Modified
4.6EPSS 0.003
CVE-2017-6602
A vulnerability in the CLI of Cisco Unified Computing System (UCS) Manager, Cisco Firepower 4100 Series Next-Generation Firewall (NGFW), and Cisco Firepower 9300 Security Appliance could allow an authenticated, local attacker to perform a command injection attack. More Information: CSCvb66189 CSCvb86775. Known Affected Releases: 2.0(1.68) 3.1(1k)A. Known Fixed Releases: 92.2(1.101) 92.1(1.1742) 92.1(1.1658) 2.1(1.38) 2.0(1.107) 2.0(1.87) 1.1(4.148) 1.1(4.138).
Published 2017-04-07 · Modified
4.4EPSS 0.008
CVE-2015-0599
The web interface in Cisco Integrated Management Controller in Cisco Unified Computing System (UCS) on C-Series Rack Servers does not properly restrict use of IFRAME elements, which makes it easier for remote attackers to conduct clickjacking attacks and unspecified other attacks via a crafted web site, related to a "cross-frame scripting (XFS)" issue, aka Bug ID CSCuf50138.
Published 2015-02-03 · Modified
4.3EPSS 0.015
CVE-2012-4116
The fabric-interconnect component in Cisco Unified Computing System (UCS) does not encrypt KVM media traffic, which allows remote attackers to obtain sensitive information, and consequently complete the authentication process for a server connection, by sniffing the network, aka Bug ID CSCtr72970.
Published 2013-10-19 · Modified
4.3EPSS 0.011
CVE-2021-1592
Cisco UCS Manager Software SSH Sessions Denial of Service Vulnerability
Published 2021-08-25 · Modified
4.3EPSS 0.010
CVE-2015-4259
The Integrated Management Controller on Cisco Unified Computing System (UCS) C servers with software 1.5(3) and 1.6(0.16) has a default SSL certificate, which makes it easier for man-in-the-middle attackers to bypass cryptographic protection mechanisms by leveraging knowledge of a private key, aka Bug IDs CSCum56133 and CSCum56177.
Published 2015-07-10 · Modified
4.3EPSS 0.008
CVE-2012-4072
The KVM subsystem in Cisco Unified Computing System (UCS) relies on a hardcoded X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers, and read keyboard and mouse events, by leveraging knowledge of this certificate's private key, aka Bug ID CSCte90327.
Published 2013-09-20 · Modified
4.3EPSS 0.006
CVE-2012-4088
The FTP server in Cisco Unified Computing System (UCS) has a hardcoded password for an unspecified user account, which makes it easier for remote attackers to read or modify files by leveraging knowledge of this password, aka Bug ID CSCtg20769.
Published 2013-09-26 · Modified
4.3EPSS 0.006
← Prev3 / 4Next →