Cisco UCS Manager Command Injection Vulnerability Allowing File Overwrite or Creation

Vulnerability

A command injection vulnerability has been identified in the CLI of Cisco UCS Manager Software. This vulnerability allows an authenticated, local attacker with administrative privileges to read, create, or overwrite any file on the file system of the underlying operating system, including system files. The issue arises from insufficient input validation of command arguments provided by the user. Exploitation of this vulnerability requires valid administrative credentials on the affected device.

Impact

Successful exploitation allows the attacker to manipulate files on the operating system, potentially overwriting critical system files or injecting malicious content that could be executed by the system.

Remediation

Cisco has released software updates to address this vulnerability. Users should consult the Cisco UCS Software release notes for upgrade instructions and to determine the best release for their environment.

Added: Aug 27, 2025, 5:36 PM
Updated: Aug 27, 2025, 5:36 PM

Vulnerability Rating

Custom Algorithm
spread
4.5
impact
5.0
exploitability
3.0
remediation
7.7
relevance
0.4
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.