Multiple Vulnerabilities in Cisco UCS Director and Cisco UCS Director Express for Big Data
75Vexday Risk Score
Patch soon. It has a working public exploit.
ssvc Attendcvss 9.8epss 60%
from disclosure to weapon0 days
Published on NVDApr 15
metasploitApr 15
exploitation probability
60%top 1% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
Multiple vulnerabilities in the REST API of Cisco UCS Director and Cisco UCS Director Express for Big Data may allow a remote attacker to bypass authentication or conduct directory traversal attacks on an affected device. For more information about these vulnerabilities, see the Details section of this advisory.
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected products
Cisco · Cisco UCS Directorpublic PoCs found — 1
cve_referencepacketstormsecurity.com/files/157955/Cisco-UCS-Director-Cloupia-Script-Remote-Code-Execution.htmlunverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.