Executive Summary

Title Cisco Unified Computing System Central Software Arbitrary Command Execution Vulnerability
Name cisco-sa-20160413-ucs First vendor Publication 2016-04-13
Vendor Cisco Last vendor Modification 2016-04-13
Severity (Vendor) N/A Revision 1.0

A vulnerability in the web framework of Cisco Unified Computing System (UCS) Central Software could allow an unauthenticated, remote attacker to execute arbitrary commands on a targeted system.

The vulnerability is due to improper input validation by the affected software. An attacker could exploit this vulnerability by sending a malicious HTTP request to an affected system. A successful exploit could allow the attacker to execute arbitrary commands on the underlying operating system.

Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.

This advisory is available at the following link: http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160413-ucs BEGIN PGP SIGNATURE Comment: GPGTools - https://gpgtools.org

Original Source

Url : http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco (...)

CWE : Common Weakness Enumeration

% Id Name
100 % CWE-78 Improper Sanitization of Special Elements used in an OS Command ('OS Command Injection') (CWE/SANS Top 25)

CPE : Common Platform Enumeration

Application 1

Snort® IPS/IDS

Date Description
2016-04-14 Cisco UCS Central Web Framework remote file include attempt
RuleID : 38543 - Revision : 1 - Type : SERVER-WEBAPP

Nessus® Vulnerability Scanner

Date Description
2016-08-25 Name : An infrastructure management application running on the remote host is affect...
File : cisco-sa-20160413-ucs.nasl - Type : ACT_GATHER_INFO

Alert History

Date Informations
2016-08-26 13:26:07
  • Multiple Updates
2016-04-18 17:27:08
  • Multiple Updates
2016-04-13 21:25:14
  • First insertion