Cisco
Cisco UCS Director: vulnerabilidades y CVE
Cisco UCS Director tiene 26 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 9 son críticas y 1 figuran en el catálogo de explotación activa de CISA.
CVE26
Últimos 12 meses0
Críticas9
Explotadas activamente1
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
🔴 Explotadas activamente (CISA KEV)
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2021-44228 | Crítica (10) | 100% | ⚠ Explotación activa | 10 dic 2021 | Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other… |
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2022-20765 | Media (4.8) | 0.58% | — | 27 may 2022 | A vulnerability in the web applications of Cisco UCS Director could allow an authenticated, remote attacker to conduct a cross-site scripting attack on an affected system. This vulnerability is due to unsanitized user… |
| CVE-2021-44228 | Crítica (10) | 100% | ⚠ Explotación activa | 10 dic 2021 | Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other… |
| CVE-2020-3464 | Media (4.8) | 0.62% | — | 17 ago 2020 | A vulnerability in the web-based management interface of Cisco UCS Director could allow an authenticated, remote attacker with administrative credentials to conduct a cross-site scripting (XSS) attack against a user of… |
| CVE-2020-3242 | Media (4.9) | 1.1% | — | 18 jun 2020 | A vulnerability in the REST API of Cisco UCS Director could allow an authenticated, remote attacker with administrative privileges to obtain confidential information from an affected device. The vulnerability exists… |
| CVE-2020-3241 | Media (6.5) | 2.0% | — | 18 jun 2020 | A vulnerability in the orchestration tasks of Cisco UCS Director could allow an authenticated, remote attacker to perform a path traversal attack on an affected device. The vulnerability is due to insufficient… |
| CVE-2020-3329 | Media (4.3) | 0.68% | — | 6 may 2020 | A vulnerability in role-based access control of Cisco Integrated Management Controller (IMC) Supervisor, Cisco UCS Director, and Cisco UCS Director Express for Big Data could allow a read-only authenticated, remote… |
| CVE-2020-3252 | Media (6.5) | 5.3% | — | 15 abr 2020 | Multiple vulnerabilities in the REST API of Cisco UCS Director and Cisco UCS Director Express for Big Data may allow a remote attacker to bypass authentication or conduct directory traversal attacks on an affected… |
| CVE-2020-3251 | Alta (8.8) | 62% | — | 15 abr 2020 | Multiple vulnerabilities in the REST API of Cisco UCS Director and Cisco UCS Director Express for Big Data may allow a remote attacker to bypass authentication or conduct directory traversal attacks on an affected… |
| CVE-2020-3250 | Crítica (9.8) | 61% | — | 15 abr 2020 | Multiple vulnerabilities in the REST API of Cisco UCS Director and Cisco UCS Director Express for Big Data may allow a remote attacker to bypass authentication or conduct directory traversal attacks on an affected… |
| CVE-2020-3249 | Alta (7.5) | 24% | — | 15 abr 2020 | Multiple vulnerabilities in the REST API of Cisco UCS Director and Cisco UCS Director Express for Big Data may allow a remote attacker to bypass authentication or conduct directory traversal attacks on an affected… |
| CVE-2020-3248 | Crítica (9.8) | 74% | — | 15 abr 2020 | Multiple vulnerabilities in the REST API of Cisco UCS Director and Cisco UCS Director Express for Big Data may allow a remote attacker to bypass authentication or conduct directory traversal attacks on an affected… |
| CVE-2020-3247 | Crítica (9.8) | 76% | — | 15 abr 2020 | Multiple vulnerabilities in the REST API of Cisco UCS Director and Cisco UCS Director Express for Big Data may allow a remote attacker to bypass authentication or conduct directory traversal attacks on an affected… |
| CVE-2020-3243 | Crítica (9.8) | 88% | — | 15 abr 2020 | Multiple vulnerabilities in the REST API of Cisco UCS Director and Cisco UCS Director Express for Big Data may allow a remote attacker to bypass authentication or conduct directory traversal attacks on an affected… |
| CVE-2020-3240 | Alta (7.3) | 39% | — | 15 abr 2020 | Multiple vulnerabilities in the REST API of Cisco UCS Director and Cisco UCS Director Express for Big Data may allow a remote attacker to bypass authentication or conduct directory traversal attacks on an affected… |
| CVE-2020-3239 | Alta (8.8) | 74% | — | 15 abr 2020 | Multiple vulnerabilities in the REST API of Cisco UCS Director and Cisco UCS Director Express for Big Data may allow a remote attacker to bypass authentication or conduct directory traversal attacks on an affected… |
| CVE-2019-16003 | Media (5.3) | 1.2% | — | 26 ene 2020 | A vulnerability in the web-based management interface of Cisco UCS Director could allow an unauthenticated, remote attacker to download system log files from an affected device. The vulnerability is due to an issue in… |
| CVE-2019-1974 | Crítica (9.8) | 4.5% | — | 21 ago 2019 | A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) Supervisor, Cisco UCS Director, and Cisco UCS Director Express for Big Data could allow an unauthenticated, remote… |
| CVE-2019-1938 | Crítica (9.8) | 4.6% | — | 21 ago 2019 | A vulnerability in the web-based management interface of Cisco UCS Director and Cisco UCS Director Express for Big Data could allow an unauthenticated, remote attacker to bypass authentication and execute arbitrary… |
| CVE-2019-1937 | Crítica (9.8) | 76% | — | 21 ago 2019 | A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) Supervisor, Cisco UCS Director, and Cisco UCS Director Express for Big Data could allow an unauthenticated, remote… |
| CVE-2019-1936 | Alta (7.2) | 39% | — | 21 ago 2019 | A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) Supervisor, Cisco UCS Director, and Cisco UCS Director Express for Big Data could allow an authenticated, remote… |
| CVE-2019-1935 | Crítica (9.8) | 83% | — | 21 ago 2019 | A vulnerability in Cisco Integrated Management Controller (IMC) Supervisor, Cisco UCS Director, and Cisco UCS Director Express for Big Data could allow an unauthenticated, remote attacker to log in to the CLI of an… |
| CVE-2019-12634 | Alta (7.5) | 2.0% | — | 21 ago 2019 | A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) Supervisor, Cisco UCS Director, and Cisco UCS Director Express for Big Data could allow an unauthenticated, remote… |
| CVE-2018-15406 | Media (6.1) | 1.2% | — | 5 oct 2018 | A vulnerability in the web-based management interface of Cisco UCS Director could allow an unauthenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the web-based… |
| CVE-2018-15405 | Media (6.5) | 1.8% | — | 5 oct 2018 | A vulnerability in the web interface for specific feature sets of Cisco Integrated Management Controller (IMC) Supervisor and Cisco UCS Director could allow an authenticated, remote attacker to access sensitive… |
| CVE-2018-0148 | Alta (8.8) | 0.83% | — | 22 feb 2018 | A vulnerability in the web-based management interface of Cisco UCS Director Software and Cisco Integrated Management Controller (IMC) Supervisor Software could allow an unauthenticated, remote attacker to conduct a… |
| CVE-2014-0709 | Alta (9.3) | 1.8% | — | 22 feb 2014 | Cisco UCS Director (formerly Cloupia) before 4.0.0.3 has a hardcoded password for the root account, which makes it easier for remote attackers to obtain administrative access via an SSH session to the CLI interface, aka… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.