First published: Wed Jul 29 2015(Updated: )
The web framework in Cisco UCS Central Software 1.3(0.99) allows remote attackers to read arbitrary files via a crafted HTTP request, aka Bug ID CSCuu41377.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco UCS Central Software | =1.3\(0.99\) |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2015-4286 is classified as high due to its potential to allow remote file access by attackers.
To fix CVE-2015-4286, upgrade to a patched version of Cisco UCS Central Software that addresses this vulnerability.
CVE-2015-4286 affects users of Cisco UCS Central Software version 1.3(0.99).
CVE-2015-4286 enables remote attackers to read arbitrary files on the system via a specially crafted HTTP request.
There are currently no documented workarounds for CVE-2015-4286; updating the software is the recommended course of action.