« Back to list

Cisco

Cisco UCS Manager: vulnerabilities and CVEs

Cisco UCS Manager has 16 published vulnerabilities, 3 of them in the last 12 months. 0 are rated critical and 0 are listed by CISA as actively exploited.

CVEs16
Last 12 months3
Critical0
Actively exploited0

All vulnerabilities in the catalogue →⭐ Follow this technology

Latest vulnerabilities

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2026-20099Medium (6.7)0.66%—Feb 25, 2026
This vulnerability is due to insufficient input validation of command arguments supplied by the user. An attacker could exploit this vulnerability by authenticating to a device and submitting crafted input to the…
CVE-2026-20037Medium (4.4)0.10%—Feb 25, 2026
—
CVE-2026-20036Medium (6.5)0.45%—Feb 25, 2026
—
CVE-2025-20342Medium (5.4)0.22%—Aug 27, 2025
A vulnerability in the Virtual Keyboard Video Monitor (vKVM) connection handling of Cisco Integrated Management Controller (IMC) could allow an authenticated, remote attacker with low privileges to conduct a stored…
CVE-2025-20317High (7.1)0.43%—Aug 27, 2025
A vulnerability in the Virtual Keyboard Video Monitor (vKVM) connection handling of Cisco Integrated Management Controller (IMC) could allow an unauthenticated, remote attacker to redirect a user to a malicious website.…
CVE-2025-20296Medium (5.4)0.23%—Aug 27, 2025
A vulnerability in the web-based management interface of Cisco UCS Manager Software could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface.…
CVE-2025-20295Medium (6)0.18%—Aug 27, 2025
A vulnerability in the CLI of Cisco UCS Manager Software could allow an authenticated, local attacker with administrative privileges to read or create a file or overwrite any file on the file system of the underlying…
CVE-2025-20294Medium (6.5)1.2%—Aug 27, 2025
Multiple vulnerabilities in the CLI and web-based management interface of Cisco UCS Manager Software could allow an authenticated, remote attacker with administrative privileges to perform command injection attacks on…
CVE-2021-1397Medium (6.1)0.83%—May 6, 2021
A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) Software could allow an unauthenticated, remote attacker to redirect a user to a malicious web page. This…
CVE-2020-10136Medium (5.3)29%—Jun 2, 2020
IP-in-IP protocol specifies IP Encapsulation within IP standard (RFC 2003, STD 1) that decapsulate and route IP-in-IP traffic is vulnerable to spoofing, access-control bypass and other unexpected behavior due to the…
CVE-2020-3173High (7.8)0.44%—Feb 26, 2020
A vulnerability in the local management (local-mgmt) CLI of Cisco UCS Manager Software could allow an authenticated, local attacker to execute arbitrary commands on the underlying operating system (OS) on an affected…
CVE-2020-3172High (8.8)1.9%—Feb 26, 2020
A vulnerability in the Cisco Discovery Protocol feature of Cisco FXOS Software and Cisco NX-OS Software could allow an unauthenticated, adjacent attacker to execute arbitrary code as root or cause a denial of service…
CVE-2020-3171High (7.8)0.48%—Feb 26, 2020
A vulnerability in the local management (local-mgmt) CLI of Cisco FXOS Software and Cisco UCS Manager Software could allow an authenticated, local attacker to execute arbitrary commands on the underlying operating…
CVE-2020-3167High (7.8)0.89%—Feb 26, 2020
A vulnerability in the CLI of Cisco FXOS Software and Cisco UCS Manager Software could allow an authenticated, local attacker to execute arbitrary commands on the underlying operating system (OS). The vulnerability is…
CVE-2020-3120Medium (6.5)1.6%—Feb 5, 2020
A vulnerability in the Cisco Discovery Protocol implementation for Cisco FXOS Software, Cisco IOS XR Software, and Cisco NX-OS Software could allow an unauthenticated, adjacent attacker to cause a reload of an affected…
CVE-2020-3119High (8.8)4.8%—Feb 5, 2020
A vulnerability in the Cisco Discovery Protocol implementation for Cisco NX-OS Software could allow an unauthenticated, adjacent attacker to execute arbitrary code or cause a reload on an affected device. The…

🎯 How it gets exploited (ATT&CK techniques)

  1. T1499 Endpoint Denial of Service1

Number of CVEs of this technology mapped to each exploitation or primary-impact technique.

📰 Related news

Other products by Cisco