Remote Code Execution Vulnerability in Cisco Integrated Management Controller Software
CVE-2017-6604

6.1MEDIUM

Key Information:

Vendor
Cisco
Vendor
CVE Published:
7 April 2017

Summary

The web interface of Cisco Integrated Management Controller (IMC) Software contains a vulnerability that allows an unauthorized remote attacker to redirect users to a harmful web page. This issue affects several Cisco Unified Computing System (UCS) products, particularly the M3 and M4 Blade and Rack Servers using Cisco IMC Software versions older than 3.1(2c)B. Exploitation of this vulnerability could result in significant security risks for affected systems.

Affected Version(s)

Cisco Integrated Management Controller Cisco Integrated Management Controller

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.