CVE-2016-1401: XSS
Cross-site scripting (XSS) vulnerability in the management interface in Cisco Unified Computing System (UCS) Central Software 1.4(1a) allows remote attackers to inject arbitrary web script or HTML via a crafted value, aka Bug ID CSCuy91250.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-1401?
CVE-2016-1401 is classified as a high severity vulnerability due to its potential impact on user data and application integrity.
How do I fix CVE-2016-1401?
To fix CVE-2016-1401, users should upgrade to a patched version of Cisco UCS Central Software that removes the XSS vulnerability.
Who is affected by CVE-2016-1401?
CVE-2016-1401 affects Cisco Unified Computing System Central Software version 1.4(1a) specifically.
What type of vulnerability is CVE-2016-1401?
CVE-2016-1401 is a cross-site scripting (XSS) vulnerability, which allows attackers to inject arbitrary web scripts into the management interface.
Can CVE-2016-1401 be exploited remotely?
Yes, CVE-2016-1401 can be exploited remotely, allowing attackers to execute malicious scripts on victims' browsers.