QID 317299

Date Published: 2023-04-04

QID 317299: Cisco UCS Fabric Interconnects Command Injection Vulnerability (cisco-sa-nxfp-cmdinj-XXBZjtR)

A vulnerability in the CLI of Cisco Cisco UCS 6200, 6300, 6400, and 6500 Series Fabric Interconnects could allow an authenticated, local attacker to inject unauthorized commands.

Affected Products:
UCS 6200 Series Fabric Interconnects UCS 6300 Series Fabric Interconnects UCS 6400 Series Fabric Interconnects UCS 6500 Series Fabric Interconnects

QID Detection Logic(Authenticated):
It checks for vulnerable version of Cisco UCS using show version Command.

A successful exploit could allow the attacker to execute unauthorized commands within the CLI.

  • CVSS V3 rated as High - 6.7 severity.
  • CVSS V2 rated as Medium - 4 severity.
  • Solution

    Customers are advised to refer to cisco-sa-nxfp-cmdinj-XXBZjtR for more information.

    CVEs related to QID 317299

    Software Advisories
    Advisory ID Software Component Link
    cisco-sa-nxfp-cmdinj-XXBZjtR URL Logo sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-nxfp-cmdinj-XXBZjtR