PT-2018-8646 · Cisco · Cisco Integrated Management Controller Supervisor+1

Published

2018-06-07

·

Updated

2019-10-09

·

CVE-2018-0149

CVSS v3.1

4.8

Medium

VectorAV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions: Cisco Integrated Management Controller Supervisor Software (affected versions not specified) Cisco UCS Director Software (affected versions not specified)
Description: A stored cross-site scripting (XSS) issue exists due to insufficient validation of user-supplied input by the web-based management interface. This could allow an authenticated, remote attacker to conduct a DOM-based XSS attack against a user of the interface. The attacker could exploit this by persuading a user to click a malicious link, potentially executing arbitrary script code in the context of the affected interface or accessing sensitive browser-based information.
Recommendations: For Cisco Integrated Management Controller Supervisor Software, update to a version that addresses the issue, specifically fixing Cisco Bug ID CSCvh12994. For Cisco UCS Director Software, update to a version that addresses the issue, specifically fixing Cisco Bug ID CSCvh12994.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-0149

Affected Products

Cisco Integrated Management Controller Supervisor
Cisco Ucs Director