cisco-sa-ucs-invcert-eOpRvCKH: Cisco Unified Computing System Central Software Improper Certificate Validation Vulnerability
A vulnerability in the certificate registration process of Cisco Unified Computing System (UCS) Central Software could allow an authenticated, adjacent attacker to register a rogue Cisco Unified Computing System Manager (UCSM). This vulnerability is due to improper certificate validation. An attacker could exploit this vulnerability by sending a crafted HTTP request to the registration API. A successful exploit could allow the attacker to register a rogue Cisco UCSM and gain access to Cisco UCS Central Software data and Cisco UCSM inventory data. Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability. This advisory is available at the following link:https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ucs-invcert-eOpRvCKH
Affected Software
Event History
Frequently Asked Questions
What is the severity of Cisco-SA-UCS-INVCERT-EOpRvCKH?
The severity of Cisco-SA-UCS-INVCERT-EOpRvCKH is classified as high due to the potential for an attacker to register a rogue UCS Manager.
How do I fix Cisco-SA-UCS-INVCERT-EOpRvCKH?
To fix Cisco-SA-UCS-INVCERT-EOpRvCKH, it is recommended to apply the latest patches and updates from Cisco for UCS Central Software.
Who is affected by Cisco-SA-UCS-INVCERT-EOpRvCKH?
Cisco-SA-UCS-INVCERT-EOpRvCKH affects users of Cisco Unified Computing System Central Software.
What type of attacks can exploit Cisco-SA-UCS-INVCERT-EOpRvCKH?
An attacker can exploit Cisco-SA-UCS-INVCERT-EOpRvCKH to register a rogue UCS Manager, potentially leading to unauthorized access to the system.
Is authentication required to exploit Cisco-SA-UCS-INVCERT-EOpRvCKH?
Yes, authentication is required for an attacker to exploit Cisco-SA-UCS-INVCERT-EOpRvCKH.