05-14-2015 03:05 AM - edited 03-01-2019 12:11 PM
https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2015-0701
Cisco UCS Central Software before 1.3(1a) allows remote attackers to execute arbitrary commands via a crafted HTTP request, aka Bug ID CSCut46961.
Can someone from TAC confirm, if this is fixed in 1.3.1a; according to the bug Report (see below), it's not.
Solved! Go to Solution.
07-06-2015 06:20 AM
As per the NIST report, this applies to UCS Central versions before 1.3(1a). According to the Cisco Bug ID CSCut46961, it was fixed in UCS Central 1.3(1a), consistent with the NIST statement as well.
Cheers,
Jacob Van Ewyk
UCS Management product manager
07-06-2015 06:20 AM
As per the NIST report, this applies to UCS Central versions before 1.3(1a). According to the Cisco Bug ID CSCut46961, it was fixed in UCS Central 1.3(1a), consistent with the NIST statement as well.
Cheers,
Jacob Van Ewyk
UCS Management product manager
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide