CVE-2015-4286: Input Validation
Published Jul 29, 2015
·Updated
The web framework in Cisco UCS Central Software 1.3(0.99) allows remote attackers to read arbitrary files via a crafted HTTP request, aka Bug ID CSCuu41377.
Affected Software
1 affected component
cisco Unified Computing System Central Software=1.3\(0.99\)
Event History
Jul 29, 2015
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-4286?
The severity of CVE-2015-4286 is classified as high due to its potential to allow remote file access by attackers.
2
How do I fix CVE-2015-4286?
To fix CVE-2015-4286, upgrade to a patched version of Cisco UCS Central Software that addresses this vulnerability.
3
Who is affected by CVE-2015-4286?
CVE-2015-4286 affects users of Cisco UCS Central Software version 1.3(0.99).
4
What type of attack does CVE-2015-4286 enable?
CVE-2015-4286 enables remote attackers to read arbitrary files on the system via a specially crafted HTTP request.
5
Is there a workaround for CVE-2015-4286?
There are currently no documented workarounds for CVE-2015-4286; updating the software is the recommended course of action.