An unspecified CGI script in Cisco FX-OS before 1.1.2 on Firepower 9000 devices and Cisco Unified Computing System (UCS) Manager before 2.2(4b), 2.2(5) before 2.2(5a), and 3.0 before 3.0(2e) allows remote attackers to execute arbitrary shell commands via a crafted HTTP request, aka Bug ID CSCur90888.
References
Link | Resource |
---|---|
http://packetstormsecurity.com/files/160991/Cisco-UCS-Manager-2.2-1d-Remote-Command-Execution.html | Exploit Third Party Advisory VDB Entry |
http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160120-ucsm | Vendor Advisory |
http://www.securitytracker.com/id/1034743 | Third Party Advisory VDB Entry |
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
History
No history.
Information
Published : 2016-01-22 11:59
Updated : 2024-02-04 18:53
NVD link : CVE-2015-6435
Mitre link : CVE-2015-6435
CVE.ORG link : CVE-2015-6435
JSON object : View
Products Affected
cisco
- unified_computing_system
- firepower_extensible_operating_system
CWE
CWE-78
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')