PT-2013-2954 · Cisco · Cisco Unified Computing System+1
Publicado
2013-04-25
·
Atualizado
2013-05-02
·
CVE-2013-1186
CVSS v2.0
7.5
Alta
| Vetor | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Cisco Unified Computing System (UCS) versions 1.x before 1.4(4)
Cisco Unified Computing System (UCS) versions 2.x before 2.0(2m)
Description
The issue allows remote attackers to bypass KVM authentication via a crafted authentication request to a Cisco Integrated Management Controller (IMC).
Recommendations
For Cisco Unified Computing System (UCS) versions 1.x before 1.4(4), update to version 1.4(4) or later.
For Cisco Unified Computing System (UCS) versions 2.x before 2.0(2m), update to version 2.0(2m) or later.
Correção
Improper Authentication
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Cisco Integrated Management Controller
Cisco Unified Computing System