Cross-Site Scripting Vulnerability in Cisco UCS Central Software
CVE-2016-1401
6.1MEDIUM
Key Information:
- Vendor
- Cisco
- Vendor
- CVE Published:
- 21 May 2016
Summary
A cross-site scripting vulnerability exists in the management interface of Cisco Unified Computing System (UCS) Central Software version 1.4(1a). This flaw enables remote attackers to inject arbitrary web scripts or HTML into the platform through a carefully crafted input value. Exploiting this vulnerability could lead to unauthorized actions taken on behalf of an unsuspecting user, thereby affecting the security of the application and the integrity of its operations. Identifying this issue is crucial for maintaining a secure web environment within UCS infrastructure.
References
CVSS V3.1
Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved