CVE-2015-4279: OS Command Injection
The Manager component in Cisco Unified Computing System (UCS) 2.2(3b) on B Blade Server devices allows local users to gain privileges for executing arbitrary CLI commands by leveraging access to the subordinate fabric interconnect, aka Bug ID CSCut32778.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-4279?
CVE-2015-4279 is classified as a high-severity vulnerability that allows local users to execute arbitrary commands.
How do I fix CVE-2015-4279?
To mitigate CVE-2015-4279, users should upgrade Cisco Unified Computing System to version 2.2(4) or later.
Who is affected by CVE-2015-4279?
CVE-2015-4279 affects local users with access to Cisco Unified Computing System version 2.2(3b) on B Blade Server devices.
What are the implications of CVE-2015-4279?
CVE-2015-4279 can lead to unauthorized command execution, potentially compromising the integrity of the system.
Is there a workaround for CVE-2015-4279?
There are no official workarounds for CVE-2015-4279, upgrading the software is the recommended solution.