Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
51 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 2.6% | — | Cisco Unified Computing SystemCisco Integrated Management Controller Supervisor | 21/8/2019 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) Software could allow an authenticated, remote attacker to inject arbitrary commands that are executed with root privileges on an affected device. The vulnerability is due to insufficient validation of command input by… | |
| Modificada | Alta (8.1) | 1.7% | — | Cisco Unified Computing SystemCisco Integrated Management Controller Supervisor | 21/8/2019 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) Software could allow an authenticated, remote attacker to make unauthorized changes to the system configuration. The vulnerability is due to insufficient authorization enforcement. An attacker could exploit this… | |
| Modificada | Alta (7.2) | 3.5% | — | Cisco Unified Computing SystemCisco Integrated Management Controller Supervisor | 21/8/2019 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) Software could allow an authenticated, remote attacker to inject arbitrary commands that are executed with root privileges on an affected device. An attacker would need to have valid administrator credentials on the… | |
| Modificada | Alta (7.2) | 2.8% | — | Cisco Unified Computing SystemCisco Integrated Management Controller Supervisor | 21/8/2019 | 17/6/2026 | A vulnerability in the Intelligent Platform Management Interface (IPMI) of Cisco Integrated Management Controller (IMC) could allow an authenticated, remote attacker to inject arbitrary commands that are executed with root privileges on the underlying operating system (OS). The vulnerability is due to insufficient… | |
| Modificada | Alta (7.5) | 2.0% | — | Cisco Integrated Management Controller SupervisorCisco UCS DirectorCisco UCS Director Express FOR BIG Data | 21/8/2019 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) Supervisor, Cisco UCS Director, and Cisco UCS Director Express for Big Data could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition. The vulnerability is due to a missing… | |
| Modificada | Media (6.7) | 0.42% | — | Cisco Unified Computing SystemCisco Integrated Management Controller | 20/6/2019 | 17/6/2026 | A vulnerability in the CLI of Cisco Integrated Management Controller (IMC) could allow an authenticated, local attacker to inject arbitrary commands that are executed with root privileges. The vulnerability is due to insufficient validation of user-supplied input at the CLI. An attacker could exploit this… | |
| Modificada | Alta (8) | 0.55% | — | Cisco Integrated Management ControllerCisco Unified Computing System | 20/6/2019 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) could allow an authenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack and perform arbitrary actions on an affected device. The vulnerability is due to insufficient CSRF protections for… | |
| Modificada | Media (5.3) | 2.2% | — | Cisco Integrated Management ControllerCisco Unified Computing System | 20/6/2019 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) could allow an unauthenticated, remote attacker to access potentially sensitive system usage information. The vulnerability is due to a lack of proper data protection mechanisms. An attacker could exploit this… | |
| Modificada | Media (5.5) | 0.35% | — | Cisco Integrated Management ControllerCisco Unified Computing System | 20/6/2019 | 17/6/2026 | A vulnerability in the firmware signature checking program of Cisco Integrated Management Controller (IMC) could allow an authenticated, local attacker to cause a buffer overflow, resulting in a denial of service (DoS) condition. The vulnerability is due to insufficient checking of an input buffer. An attacker could… | |
| Modificada | Media (5.3) | 1.5% | — | Cisco Integrated Management ControllerCisco Unified Computing System | 20/6/2019 | 17/6/2026 | A vulnerability in the configuration import utility of Cisco Integrated Management Controller (IMC) could allow an unauthenticated, remote attacker to have write access and upload arbitrary data to the filesystem. The vulnerability is due to a failure to delete temporarily uploaded files. An attacker could exploit… | |
| Modificada | Media (5.5) | 0.39% | — | Cisco Integrated Management ControllerCisco Unified Computing System | 20/6/2019 | 17/6/2026 | A vulnerability in the web server of Cisco Integrated Management Controller (IMC) could allow an authenticated, local attacker to cause a buffer overflow, resulting in a denial of service (DoS) condition on an affected device. The vulnerability is due to incorrect bounds checking. An attacker could exploit this… | |
| Modificada | Media (6.5) | 1.2% | — | Cisco Integrated Management ControllerCisco Unified Computing System | 20/6/2019 | 17/6/2026 | A vulnerability in the Server Utilities of Cisco Integrated Management Controller (IMC) could allow an authenticated, remote attacker to gain unauthorized access to sensitive user information from the configuration data that is stored on the affected system. The vulnerability is due to insufficient protection of data… | |
| Modificada | Crítica (9.8) | 1.7% | — | Cisco Integrated Management Controller | 8/11/2018 | 17/6/2026 | A vulnerability in the web framework code of Cisco Integrated Management Controller (IMC) Supervisor could allow an unauthenticated, remote attacker to execute arbitrary SQL queries. The vulnerability is due to a lack of proper validation of user-supplied input in SQL queries. An attacker could exploit this… | |
| Modificada | Media (6.5) | 1.1% | — | Cisco Unified Computing System DirectorCisco Integrated Management Controller Supervisor | 5/10/2018 | 17/6/2026 | A vulnerability in the web interface of Cisco Integrated Management Controller (IMC) Supervisor and Cisco UCS Director could allow an authenticated, remote attacker to cause a denial of service (DoS) condition on an affected system. The vulnerability is due to insufficient restrictions on the size or total amount of… | |
| Modificada | Media (4.8) | 1.3% | — | Cisco Integrated Management Controller Supervisor | 7/6/2018 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Integrated Management Controller Supervisor Software and Cisco UCS Director Software could allow an authenticated, remote attacker to conduct a Document Object Model-based (DOM-based), stored cross-site scripting (XSS) attack against a user of the… | |
| Modificada | Alta (8.8) | 2.6% | — | Cisco Integrated Management Controller Supervisor | 20/4/2017 | 17/6/2026 | A vulnerability in the web-based GUI of Cisco Integrated Management Controller (IMC) 3.0(1c) could allow an authenticated, remote attacker to execute arbitrary commands on an affected system. The vulnerability exists because the affected software does not sufficiently sanitize user-supplied HTTP input. An attacker… | |
| Modificada | Media (5.4) | 0.93% | — | Cisco Integrated Management Controller Supervisor | 20/4/2017 | 17/6/2026 | A vulnerability in the web-based GUI of Cisco Integrated Management Controller (IMC) 3.0(1c) could allow an authenticated, remote attacker to perform a cross-site scripting (XSS) attack. The vulnerability is due to insufficient validation of user-supplied input by the affected software. An attacker could exploit this… | |
| Modificada | Media (5.4) | 0.97% | — | Cisco Integrated Management Controller Supervisor | 20/4/2017 | 17/6/2026 | A vulnerability in the session identification management functionality of the web-based GUI of Cisco Integrated Management Controller (IMC) 3.0(1c) could allow an unauthenticated, remote attacker to hijack a valid user session on an affected system. The vulnerability exists because the affected software does not… | |
| Modificada | Alta (8.8) | 4.2% | — | Cisco Integrated Management Controller Supervisor | 20/4/2017 | 17/6/2026 | A vulnerability in the web-based GUI of Cisco Integrated Management Controller (IMC) 3.0(1c) could allow an authenticated, remote attacker to execute arbitrary code on an affected system. The vulnerability exists because the affected software does not sufficiently sanitize specific values that are received as part of… | |
| Modificada | Media (6.8) | 2.2% | — | Cisco Integrated Management Controller Supervisor | 15/12/2015 | 17/6/2026 | The Supervisor 1.0.0.0 and 1.0.0.1 in Cisco Integrated Management Controller (IMC) before 2.0(9) allows remote authenticated users to cause a denial of service (IP interface outage) via crafted parameters in an HTTP request, aka Bug ID CSCuv38286. | |
| Modificada | Alta (9.4) | 2.8% | — | Cisco Integrated Management Controller SupervisorCisco Unified Computing System Director | 4/9/2015 | 17/6/2026 | The JavaServer Pages (JSP) component in Cisco Integrated Management Controller (IMC) Supervisor before 1.0.0.1 and UCS Director (formerly Cloupia Unified Infrastructure Controller) before 5.2.0.1 allows remote attackers to write to arbitrary files via crafted HTTP requests, aka Bug IDs CSCus36435 and CSCus62625. | |
| Modificada | Media (5) | 2.6% | — | Cisco Integrated Management ControllerCisco Unified Computing System E140dCisco Unified Computing System E140dpCisco Unified Computing System E140s M1+4 | 10/9/2014 | 17/6/2026 | The SSH module in the Integrated Management Controller (IMC) before 2.3.1 in Cisco Unified Computing System on E-Series blade servers allows remote attackers to cause a denial of service (IMC hang) via a crafted SSH packet, aka Bug ID CSCuo69206. | |
| Modificada | Alta (7.5) | 2.1% | — | Cisco Unified Computing System Infrastructure AND Unified Computing System SoftwareCisco Unified Computing System 6120xp Fabric InterconnectCisco Unified Computing System 6140xp Fabric InterconnectCisco Unified Computing System 6248up Fabric Interconnect+2 | 25/4/2013 | 16/6/2026 | Cisco Unified Computing System (UCS) 1.x before 1.4(4) and 2.x before 2.0(2m) allows remote attackers to bypass KVM authentication via a crafted authentication request to a Cisco Integrated Management Controller (IMC), aka Bug ID CSCts53746. | |
| Modificada | Alta (9.3) | 1.8% | — | Cisco Unified Computing System Infrastructure AND Unified Computing System SoftwareCisco Unified Computing System 6120xp Fabric InterconnectCisco Unified Computing System 6140xp Fabric InterconnectCisco Unified Computing System 6248up Fabric Interconnect+2 | 25/4/2013 | 16/6/2026 | The web interface in the Manager component in Cisco Unified Computing System (UCS) 1.x and 2.x before 2.0(2m) allows remote attackers to obtain sensitive information by reading a (1) technical-support bundle file or (2) on-device configuration backup, aka Bug ID CSCtq86543. | |
| Modificada | Alta (7.8) | 1.3% | — | Cisco Unified Computing System Infrastructure AND Unified Computing System SoftwareCisco Unified Computing System 6120xp Fabric InterconnectCisco Unified Computing System 6140xp Fabric InterconnectCisco Unified Computing System 6248up Fabric Interconnect+2 | 25/4/2013 | 16/6/2026 | The management API in the XML API management service in the Manager component in Cisco Unified Computing System (UCS) 1.x before 1.2(1b) allows remote attackers to cause a denial of service (service outage) via a malformed request, aka Bug ID CSCtg48206. |