CVE-2016-1352: OS Command Injection
Published Apr 14, 2016
·Updated
Cisco Unified Computing System (UCS) Central Software 1.3(1b) and earlier allows remote attackers to execute arbitrary OS commands via a crafted HTTP request, aka Bug ID CSCuv33856.
Affected Software
1 affected component
cisco Unified Computing System Central Software=1.3\(0.1\)
Event History
Apr 14, 2016
CVE Published
via MITRE·01:00 AM
Data Sourced
via MITRE·01:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-1352?
CVE-2016-1352 has been classified as a critical severity vulnerability.
2
How do I fix CVE-2016-1352?
To fix CVE-2016-1352, upgrade to Cisco Unified Computing System Central Software version 1.3(1c) or later.
3
Who is affected by CVE-2016-1352?
CVE-2016-1352 affects users of Cisco Unified Computing System Central Software version 1.3(1b) and earlier.
4
What type of vulnerability is CVE-2016-1352?
CVE-2016-1352 is a remote command execution vulnerability.
5
What can attackers do with CVE-2016-1352?
Attackers exploiting CVE-2016-1352 can execute arbitrary OS commands on the affected system.