[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248585

 
 

909

 
 

195621

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2015-0599Date: (C)2015-02-04   (M)2023-12-22


The web interface in Cisco Integrated Management Controller in Cisco Unified Computing System (UCS) on C-Series Rack Servers does not properly restrict use of IFRAME elements, which makes it easier for remote attackers to conduct clickjacking attacks and unspecified other attacks via a crafted web site, related to a "cross-frame scripting (XFS)" issue, aka Bug ID CSCuf50138.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 4.3
Exploit Score: 8.6
Impact Score: 2.9
 
CVSS V2 Metrics:
Access Vector: NETWORK
Access Complexity: MEDIUM
Authentication: NONE
Confidentiality: NONE
Integrity: PARTIAL
Availability: NONE
  
Reference:
http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2015-0599
SECUNIA-62762
BID-72509
cisco-ucs-cve20150599-xfs(100614)
http://tools.cisco.com/security/center/viewAlert.x?alertId=37324

CPE    1
cpe:/h:cisco:unified_computing_system:-
CWE    1
CWE-254

© SecPod Technologies