
CVE-2017-12341
https://notcve.org/view.php?id=CVE-2017-12341
30 Nov 2017 — A vulnerability in the CLI of Cisco NX-OS System Software could allow an authenticated, local attacker to perform a command injection attack. An attacker would need valid administrator credentials to perform this exploit. The vulnerability is due to insufficient input validation during the installation of a software patch. An attacker could exploit this vulnerability by installing a crafted patch image with the vulnerable operation occurring prior to patch activation. An exploit could allow the attacker to ... • http://www.securitytracker.com/id/1039939 • CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection') •

CVE-2017-12348
https://notcve.org/view.php?id=CVE-2017-12348
30 Nov 2017 — Multiple vulnerabilities in the web-based management interface of Cisco UCS Central Software could allow a remote attacker to conduct a cross-site scripting (XSS) attack against a user of the affected interface or hijack a valid session ID from a user of the affected interface. Cisco Bug IDs: CSCvf71978, CSCvf71986. Múltiples vulnerabilidades en la interfaz de gestión web de Cisco UCS Central Software podría permitir que un atacante remoto lleve a cabo un ataque de Cross-Site Scripting (XSS) contra un usuar... • http://www.securityfocus.com/bid/102018 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2017-12349
https://notcve.org/view.php?id=CVE-2017-12349
30 Nov 2017 — Multiple vulnerabilities in the web-based management interface of Cisco UCS Central Software could allow a remote attacker to conduct a cross-site scripting (XSS) attack against a user of the affected interface or hijack a valid session ID from a user of the affected interface. Cisco Bug IDs: CSCvf71978, CSCvf71986. Múltiples vulnerabilidades en la interfaz de gestión web de Cisco UCS Central Software podría permitir que un atacante remoto lleve a cabo un ataque de Cross-Site Scripting (XSS) contra un usuar... • http://www.securityfocus.com/bid/102018 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2017-12243 – Cisco UCS Platform Emulator 3.1(2ePE1) - Remote Code Execution
https://notcve.org/view.php?id=CVE-2017-12243
02 Nov 2017 — A vulnerability in the Cisco Unified Computing System (UCS) Manager, Cisco Firepower 4100 Series Next-Generation Firewall (NGFW), and Cisco Firepower 9300 Security Appliance could allow an authenticated, local attacker to obtain root shell privileges on the device, aka Command Injection. The vulnerability is due to improper validation of string input in the shell application. An attacker could exploit this vulnerability through the use of malicious commands. A successful exploit could allow the attacker to ... • https://www.exploit-db.com/exploits/44052 • CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') •

CVE-2017-12255
https://notcve.org/view.php?id=CVE-2017-12255
21 Sep 2017 — A vulnerability in the CLI of Cisco UCS Central Software could allow an authenticated, local attacker to gain shell access. The vulnerability is due to insufficient input validation of commands entered in the CLI, aka a Restricted Shell Break Vulnerability. An attacker could exploit this vulnerability by entering a specific command with crafted arguments. An exploit could allow the attacker to gain shell access to the underlying system. Cisco Bug IDs: CSCve70762. • http://www.securityfocus.com/bid/100932 • CWE-20: Improper Input Validation •

CVE-2017-6633
https://notcve.org/view.php?id=CVE-2017-6633
22 May 2017 — A vulnerability in the TCP throttling process of Cisco UCS C-Series Rack Servers 3.0(0.234) could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to insufficient rate-limiting protection. An attacker could exploit this vulnerability by sending a high rate of TCP SYN packets to a specific TCP listening port on an affected device. An exploit could allow the attacker to cause a specific TCP listening port to stop accepting n... • http://www.securityfocus.com/bid/98525 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •

CVE-2017-6598
https://notcve.org/view.php?id=CVE-2017-6598
07 Apr 2017 — A vulnerability in the debug plug-in functionality of the Cisco Unified Computing System (UCS) Manager, Cisco Firepower 4100 Series Next-Generation Firewall (NGFW), and Cisco Firepower 9300 Security Appliance could allow an authenticated, local attacker to execute arbitrary commands, aka Privilege Escalation. More Information: CSCvb86725 CSCvb86797. Known Affected Releases: 2.0(1.68) 3.1(1k)A. Known Fixed Releases: 92.2(1.105) 92.1(1.1733) 2.1(1.69). Una vulnerabilidad en la funcionalidad de complemento de ... • http://www.securityfocus.com/bid/97429 • CWE-862: Missing Authorization •

CVE-2017-3817
https://notcve.org/view.php?id=CVE-2017-3817
07 Apr 2017 — A vulnerability in the role-based resource checking functionality of Cisco Unified Computing System (UCS) Director could allow an authenticated, remote attacker to view unauthorized information for any virtual machine in a UCS domain. More Information: CSCvc32434. Known Affected Releases: 5.5(0.1) 6.0(0.0). Una vulnerabilidad en la funcionalidad de comprobación de recursos basada en roles del Director del Unified Computing System (UCS) de Cisco podría permitir a un atacante remoto autenticado ver informació... • http://www.securityfocus.com/bid/97430 • CWE-863: Incorrect Authorization •

CVE-2017-6597
https://notcve.org/view.php?id=CVE-2017-6597
07 Apr 2017 — A vulnerability in the local-mgmt CLI command of the Cisco Unified Computing System (UCS) Manager, Cisco Firepower 4100 Series Next-Generation Firewall (NGFW), and Cisco Firepower 9300 Security Appliance could allow an authenticated, local attacker to perform a command injection attack. More Information: CSCvb61394 CSCvb86816. Known Affected Releases: 2.0(1.68) 3.1(1k)A. Known Fixed Releases: 92.2(1.101) 92.1(1.1658) 2.0(1.115). Una vulnerabilidad en el comando local-mgmt de la CLI del Administrador del Uni... • http://www.securityfocus.com/bid/97476 • CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') •

CVE-2017-6600
https://notcve.org/view.php?id=CVE-2017-6600
07 Apr 2017 — A vulnerability in the CLI of the Cisco Unified Computing System (UCS) Manager, Cisco Firepower 4100 Series Next-Generation Firewall (NGFW), and Cisco Firepower 9300 Security Appliance could allow an authenticated, local attacker to perform a command injection attack. More Information: CSCvb61351 CSCvb61637. Known Affected Releases: 2.0(1.68) 3.1(1k)A. Known Fixed Releases: 92.2(1.101) 92.1(1.1645) 2.0(1.82) 1.1(4.136. Una vulnerabilidad en el CLI del Unified Computing System (UCS) de Cisco, Cisco Firepower... • http://www.securityfocus.com/bid/97439 • CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') •