PT-2017-2986 · Cisco · Cisco Ucs Central

Published

2017-09-20

·

Updated

2019-10-09

·

CVE-2017-12255

CVSS v2.0

7.2

High

VectorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Cisco UCS Central Software (affected versions not specified)
Description The issue is related to insufficient input validation of commands entered in the CLI, which could allow an authenticated, local attacker to gain shell access by entering a specific command with crafted arguments. This could enable the attacker to exploit the vulnerability and gain shell access to the underlying system.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2017-02331
CVE-2017-12255

Affected Products

Cisco Ucs Central