First published: Thu May 07 2015(Updated: )
Cisco UCS Central Software before 1.3(1a) allows remote attackers to execute arbitrary commands via a crafted HTTP request, aka Bug ID CSCut46961.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco UCS Central Software | =1.0_base | |
Cisco UCS Central Software | =1.1_base | |
Cisco UCS Central Software | =1.2\(1a\) | |
Cisco UCS Central Software | =1.2\(1d\) | |
Cisco UCS Central Software | =1.2\(1e\) | |
Cisco UCS Central Software | =1.2\(1f\) |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-0701 is classified as a high severity vulnerability due to its potential to allow remote attackers to execute arbitrary commands.
To fix CVE-2015-0701, you should upgrade to Cisco UCS Central Software version 1.3(1a) or later.
CVE-2015-0701 allows attackers to execute arbitrary commands on affected Cisco UCS Central Software installations.
CVE-2015-0701 affects Cisco UCS Central Software versions 1.0_base, 1.1_base, 1.2(1a), and some other 1.2 versions.
There are no official workarounds for CVE-2015-0701; upgrading to a patched version is the recommended solution.