First published: Mon Jul 20 2015(Updated: )
The Manager component in Cisco Unified Computing System (UCS) 2.2(3b) on B Blade Server devices allows local users to gain privileges for executing arbitrary CLI commands by leveraging access to the subordinate fabric interconnect, aka Bug ID CSCut32778.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco Unified Computing System software | =2.2\(3b\) |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-4279 is classified as a high-severity vulnerability that allows local users to execute arbitrary commands.
To mitigate CVE-2015-4279, users should upgrade Cisco Unified Computing System to version 2.2(4) or later.
CVE-2015-4279 affects local users with access to Cisco Unified Computing System version 2.2(3b) on B Blade Server devices.
CVE-2015-4279 can lead to unauthorized command execution, potentially compromising the integrity of the system.
There are no official workarounds for CVE-2015-4279, upgrading the software is the recommended solution.