6.8

CVE-2015-0633

The Integrated Management Controller (IMC) in Cisco Unified Computing System (UCS) 1.4(7h) and earlier on C-Series servers allows remote attackers to bypass intended access restrictions by sending crafted DHCP response packets on the local network, aka Bug ID CSCuf52876.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Cisco ≫ Unified Computing System Version 1.4
   Cisco ≫ C200 M1
   Cisco ≫ C200 M2
   Cisco ≫ C210 M2
   Cisco ≫ C22 M3
   Cisco ≫ C220 M3
   Cisco ≫ C220 M4
   Cisco ≫ C24 M3
   Cisco ≫ C240 M3
   Cisco ≫ C240 M4
   Cisco ≫ C250 M1
   Cisco ≫ C250 M2
   Cisco ≫ C260 M2
   Cisco ≫ C3160
   Cisco ≫ C420 M2
   Cisco ≫ C420 M3
   Cisco ≫ C460 M1
   Cisco ≫ C460 M2
   Cisco ≫ C460 M4
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.04% 0.594
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 6.8 6.5 7.8
AV:A/AC:L/Au:N/C:N/I:P/A:C
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2015-0633
Vendor Advisory
http://tools.cisco.com/security/center/viewAlert.x?alertId=37575
Vendor Advisory
http://www.securityfocus.com/bid/72760
http://www.securityfocus.com/bid/85711
http://www.securitytracker.com/id/1031796