Cisco UCS Manager
cpe:2.3:a:cisco:ucs_manager:*:*:*:*:*:*:*
- <= 4.1
- <= 4.2
- 4.3
- 6.0
A vulnerability exists in the NX-OS CLI privilege levels of Cisco UCS Manager Software, allowing an authenticated, local attacker with read-only privileges to modify files and perform unauthorized actions on the system. This issue arises from the assignment of unnecessary privileges to users. An attacker could exploit this by authenticating as a read-only user and accessing the NX-OS CLI, potentially leading to the creation or overwriting of files or the execution of limited privileged actions on the device.
Exploitation could allow the attacker to escalate privileges, enabling them to modify files or perform restricted actions on the affected system.
Cisco has released software updates to address this vulnerability. Users should upgrade to the fixed releases mentioned in the advisory. For guidance on which release to upgrade to, consult the Recommended Releases documents in the release notes for the device.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.