Vulnslist

find the latest Cisco vulnerabilities

Cisco Unified Computing System Blade Server Information Disclosure Vulnerability

cisco-sa-20151102-ucs · Medium · Published · Updated

A vulnerability in the web interface of the Cisco Unified Computing System (UCS) Blade Server could allow an unauthenticated, remote attacker to obtain information about the UCS software version. The vulnerability is due to the verbose output that is returned when a specific URL is submitted to an affected system. An attacker could exploit this vulnerability by browsing to a specific URL. A successful exploit could allow an attacker to obtain information from the UCS. The information could be used for reconnaissance attacks. Cisco has not released software updates that address this vulnerability. There are no workarounds that mitigate this vulnerability. This advisory is available at the following link: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20151102-ucs

Workarounds

There are no workarounds that mitigate this vulnerability.

CVEsCVE-2015-6355
Cisco Bug IDsCSCuw87226
CVSS ScoreBase 5.0
Base 5.0 AV:N/AC:L/Au:N/C:P/I:N/A:N/E:F/RL:U/RC:C
Product Names From Source
Cisco Unified Computing System (Managed)

Related Products

Product CVE Evidence
Cisco RV Series Routers CVE-2015-6355 Cisco OpenVuln
Cisco Nexus Dashboard CVE-2015-6355 Cisco OpenVuln
Cisco Unified Computing System (Managed) CVE-2015-6355 Cisco OpenVuln