First published: Sat May 21 2016(Updated: )
Cross-site scripting (XSS) vulnerability in the management interface in Cisco Unified Computing System (UCS) Central Software 1.4(1a) allows remote attackers to inject arbitrary web script or HTML via a crafted value, aka Bug ID CSCuy91250.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco UCS Central Software | =1.4\(1a\) |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-1401 is classified as a high severity vulnerability due to its potential impact on user data and application integrity.
To fix CVE-2016-1401, users should upgrade to a patched version of Cisco UCS Central Software that removes the XSS vulnerability.
CVE-2016-1401 affects Cisco Unified Computing System Central Software version 1.4(1a) specifically.
CVE-2016-1401 is a cross-site scripting (XSS) vulnerability, which allows attackers to inject arbitrary web scripts into the management interface.
Yes, CVE-2016-1401 can be exploited remotely, allowing attackers to execute malicious scripts on victims' browsers.