Multiple Vulnerabilities in Cisco Unified Computing System (cisco-sa-20130424-ucsmulti)

critical Nessus Plugin ID 69921

Synopsis

The remote device is missing a vendor-supplied security patch.

Description

Managed and standalone Cisco Unified Computing System (UCS) deployments contain one or more of the following vulnerabilities :

- Cisco Unified Computing System LDAP User Authentication Bypass Vulnerability (CVE-2013-1182)

- Cisco Unified Computing System IPMI Buffer Overflow Vulnerability (CVE-2013-1183)

- Cisco Unified Computing Management API Denial of Service Vulnerability (CVE-2013-1184)

- Cisco Unified Computing System Information Disclosure Vulnerability (CVE-2013-1185)

- Cisco Unified Computing System KVM Authentication Bypass Vulnerability (CVE-2013-1186)

Cisco has released free software updates that address these vulnerabilities.

Solution

Upgrade to version 2.1.1e as recommended in Cisco Security Advisory cisco-sa-20130424-ucsmulti.

See Also

http://www.nessus.org/u?62d66b5e

Plugin Details

Severity: Critical

ID: 69921

File Name: cisco-sa-20130424-ucsmulti.nasl

Version: 1.6

Type: remote

Family: CISCO

Published: 9/17/2013

Updated: 3/8/2024

Supported Sensors: Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 5.9

CVSS v2

Risk Factor: Critical

Base Score: 10

Temporal Score: 7.4

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Information

CPE: cpe:/a:cisco:unified_computing_system_software

Required KB Items: www/cisco_ucs_manager

Exploit Ease: No known exploits are available

Patch Publication Date: 4/24/2013

Vulnerability Publication Date: 4/24/2013

Reference Information

CVE: CVE-2013-1182, CVE-2013-1183, CVE-2013-1184, CVE-2013-1185, CVE-2013-1186

BID: 59451, 59453, 59455, 59457, 59459

CISCO-SA: cisco-sa-20130424-ucsmulti

IAVA: 2013-A-0099-S

CISCO-BUG-ID: CSCtc91207, CSCtd32371, CSCtg48206, CSCtq86543, CSCts53746