« Volver al listado

Cisco

Cisco Unified Computing System: vulnerabilidades y CVE

Cisco Unified Computing System tiene 116 vulnerabilidades publicadas, 11 de ellas en los últimos 12 meses. 2 son críticas y 1 figuran en el catálogo de explotación activa de CISA.

CVE116
Últimos 12 meses11
Críticas2
Explotadas activamente1

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

🔴 Explotadas activamente (CISA KEV)

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2021-44228Crítica (10)100%⚠ Explotación activa10 dic 2021
Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other…

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-20288Media (6.5)0.64%—5 ago 2026
—
CVE-2026-20200Alta (8.8)0.73%—5 ago 2026
—
CVE-2026-20097Media (6.5)0.39%—1 abr 2026
A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with admin-level privileges to execute arbitrary code as the root user. This vulnerability is due to…
CVE-2026-20096Media (6.5)0.72%—1 abr 2026
A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with admin-level privileges to perform command injection attacks on an affected system and execute…
CVE-2026-20095Media (6.5)0.93%—1 abr 2026
A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with admin-level privileges to perform command injection attacks on an affected system and execute…
CVE-2026-20094Alta (8.8)1.1%—1 abr 2026
A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with read-only privileges to perform command injection attacks on an affected system and execute arbitrary…
CVE-2026-20090Media (4.8)0.24%—1 abr 2026
A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with administrative privileges to conduct a stored XSS attack against a user of the interface. This…
CVE-2026-20089Media (4.8)0.24%—1 abr 2026
A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with administrative privileges to conduct a stored XSS attack against a user of the interface. This…
CVE-2026-20088Media (4.8)0.22%—1 abr 2026
A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with administrative privileges to conduct a stored XSS attack against a user of the interface. This…
CVE-2026-20087Media (4.8)0.17%—1 abr 2026
A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with administrative privileges to conduct a stored XSS attack against a user of the interface. This…
CVE-2026-20085Media (6.1)0.18%—1 abr 2026
A vulnerability in the web-based management interface of Cisco IMC could allow an unauthenticated, remote attacker to conduct a reflected XSS attack against a user of the interface. This vulnerability is due to…
CVE-2020-26062Media (5.3)0.84%—18 nov 2024
A vulnerability in Cisco Integrated Management Controller could allow an unauthenticated, remote attacker to enumerate valid usernames within the vulnerable application. The vulnerability is due to differences in…
CVE-2024-20365Alta (7.2)0.89%—2 oct 2024
A vulnerability in the Redfish API of Cisco UCS B-Series, Cisco UCS Managed C-Series, and Cisco UCS X-Series Servers could allow an authenticated, remote attacker with administrative privileges to perform command…
CVE-2024-20294Media (6.6)0.32%—29 feb 2024
A vulnerability in the Link Layer Discovery Protocol (LLDP) feature of Cisco FXOS Software and Cisco NX-OS Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on an…
CVE-2021-44228Crítica (10)100%⚠ Explotación activa10 dic 2021
Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other…
CVE-2021-34736Alta (7.5)1.3%—21 oct 2021
A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) Software could allow an unauthenticated, remote attacker to cause the web-based management interface to unexpectedly…
CVE-2021-1592Media (4.3)1.0%—25 ago 2021
A vulnerability in the way Cisco UCS Manager software handles SSH sessions could allow an authenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to…
CVE-2021-1590Media (5.3)1.4%—25 ago 2021
A vulnerability in the implementation of the system login block-for command for Cisco NX-OS Software could allow an unauthenticated, remote attacker to cause a login process to unexpectedly restart, causing a denial of…
CVE-2021-1387Alta (8.6)1.4%—24 feb 2021
A vulnerability in the network stack of Cisco NX-OS Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability exists because the…
CVE-2021-1368Alta (8.8)0.46%—24 feb 2021
A vulnerability in the Unidirectional Link Detection (UDLD) feature of Cisco FXOS Software and Cisco NX-OS Software could allow an unauthenticated, adjacent attacker to execute arbitrary code with administrative…
CVE-2019-1736Media (6.6)0.25%—23 sept 2020
A vulnerability in the firmware of the Cisco UCS C-Series Rack Servers could allow an authenticated, physical attacker to bypass Unified Extensible Firmware Interface (UEFI) Secure Boot validation checks and load a…
CVE-2020-10136Media (5.3)29%—2 jun 2020
IP-in-IP protocol specifies IP Encapsulation within IP standard (RFC 2003, STD 1) that decapsulate and route IP-in-IP traffic is vulnerable to spoofing, access-control bypass and other unexpected behavior due to the…
CVE-2019-1966Alta (7.8)0.36%—30 ago 2019
A vulnerability in a specific CLI command within the local management (local-mgmt) context for Cisco UCS Fabric Interconnect Software could allow an authenticated, local attacker to gain elevated privileges as the root…
CVE-2019-1908Alta (7.5)2.0%—21 ago 2019
A vulnerability in the Intelligent Platform Management Interface (IPMI) implementation of Cisco Integrated Management Controller (IMC) could allow an unauthenticated, remote attacker to view sensitive system…
CVE-2019-1907Alta (8.8)1.4%—21 ago 2019
A vulnerability in the web server of Cisco Integrated Management Controller (IMC) could allow an authenticated, remote attacker to set sensitive configuration values and gain elevated privileges. The vulnerability is…
CVE-2019-1900Alta (7.5)1.9%—21 ago 2019
A vulnerability in the web server of Cisco Integrated Management Controller (IMC) could allow an unauthenticated, remote attacker to cause the web server process to crash, causing a denial of service (DoS) condition on…
CVE-2019-1896Alta (7.2)1.8%—21 ago 2019
A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) could allow an authenticated, remote attacker to inject arbitrary commands and obtain root privileges. The…
CVE-2019-1885Alta (7.2)3.8%—21 ago 2019
A vulnerability in the Redfish protocol of Cisco Integrated Management Controller (IMC) could allow an authenticated, remote attacker to inject and execute arbitrary commands with root privileges on an affected device.…
CVE-2019-1883Alta (7.8)0.41%—21 ago 2019
A vulnerability in the command-line interface of Cisco Integrated Management Controller (IMC) could allow an authenticated, local attacker with read-only credentials to inject arbitrary commands that could allow them to…
CVE-2019-1871Alta (7.2)3.3%—21 ago 2019
A vulnerability in the Import Cisco IMC configuration utility of Cisco Integrated Management Controller (IMC) could allow an authenticated, remote attacker to cause a denial of service (DoS) condition and implement…

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1068 Exploitation for Privilege Escalation2
  2. T1078 Valid Accounts2
  3. T1190 Exploit Public-Facing Application2
  4. T1059.007 JavaScript1
  5. T1542.001 System Firmware1

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.

📰 Noticias relacionadas

Otros productos de Cisco