Cross-Site Scripting Vulnerability in Cisco UCS Central Software
CVE-2016-1401

6.1MEDIUM

Key Information:

Vendor
Cisco
Vendor
CVE Published:
21 May 2016

Summary

A cross-site scripting vulnerability exists in the management interface of Cisco Unified Computing System (UCS) Central Software version 1.4(1a). This flaw enables remote attackers to inject arbitrary web scripts or HTML into the platform through a carefully crafted input value. Exploiting this vulnerability could lead to unauthorized actions taken on behalf of an unsuspecting user, thereby affecting the security of the application and the integrity of its operations. Identifying this issue is crucial for maintaining a secure web environment within UCS infrastructure.

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.