First published: Thu Apr 25 2013(Updated: )
Cisco Unified Computing System (UCS) 1.x before 1.4(4) and 2.x before 2.0(2m) allows remote attackers to bypass KVM authentication via a crafted authentication request to a Cisco Integrated Management Controller (IMC), aka Bug ID CSCts53746.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco Unified Computing System | =1.0 | |
Cisco Unified Computing System | =1.0\(2k\) | |
Cisco Unified Computing System | =1.1 | |
Cisco Unified Computing System | =1.1\(1m\) | |
Cisco Unified Computing System | =1.2 | |
Cisco Unified Computing System | =1.2\(1\) | |
Cisco Unified Computing System | =1.2\(1a\) | |
Cisco Unified Computing System | =1.2\(1d\) | |
Cisco Unified Computing System | =1.3\(1c\) | |
Cisco Unified Computing System | =1.3\(1m\) | |
Cisco Unified Computing System | =1.3\(1n\) | |
Cisco Unified Computing System | =1.3\(1o\) | |
Cisco Unified Computing System | =1.3\(1p\) | |
Cisco Unified Computing System | =1.3\(1q\) | |
Cisco Unified Computing System | =1.3\(1t\) | |
Cisco Unified Computing System | =1.3\(1w\) | |
Cisco Unified Computing System | =1.3\(1y\) | |
Cisco Unified Computing System | =1.4\(1j\) | |
Cisco Unified Computing System | =1.4\(1m\) | |
Cisco Unified Computing System | =1.4\(3i\) | |
Cisco Unified Computing System | =1.4\(3l\) | |
Cisco Unified Computing System | =1.4\(3m\) | |
Cisco Unified Computing System | =1.4\(3q\) | |
Cisco Unified Computing System | =1.4\(3s\) | |
Cisco Unified Computing System | =1.4\(3u\) | |
Cisco Unified Computing System | =1.4\(3y\) | |
Cisco Unified Computing System | =2.0\(1q\) | |
Cisco Unified Computing System | =2.0\(1s\) | |
Cisco Unified Computing System | =2.0\(1t\) | |
Cisco Unified Computing System | =2.0\(1w\) | |
Cisco Unified Computing System | =2.0\(1x\) | |
Cisco Unified Computing System 6120xp Fabric Interconnect | ||
Cisco Unified Computing System 6140xp Fabric Interconnect | ||
Cisco UCS 6248UP Fabric Interconnect | ||
Cisco UCS 6296UP Fabric Interconnect | ||
Cisco Unified Computing System Integrated Management Controller |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-1186 is considered a critical vulnerability due to its potential for remote exploitation without authentication.
To fix CVE-2013-1186, you should upgrade to Cisco Unified Computing System version 1.4(4) or later, or 2.0(2m) or later.
CVE-2013-1186 affects Cisco Unified Computing System versions 1.x before 1.4(4) and 2.x before 2.0(2m).
Yes, CVE-2013-1186 can be exploited remotely by sending a specially crafted authentication request.
It is recommended to apply the necessary software updates and restrict access to the management interfaces to minimize risk associated with CVE-2013-1186.