ID

VAR-201505-0129


CVE

CVE-2015-0701


TITLE

Cisco Unified Computing System Central Software Arbitrary Command Execution Vulnerability

Trust: 1.1

sources: BID: 74491 // JVNDB: JVNDB-2015-002540

DESCRIPTION

Cisco UCS Central Software before 1.3(1a) allows remote attackers to execute arbitrary commands via a crafted HTTP request, aka Bug ID CSCut46961. An attacker can exploit this issue to execute system commands on the underlying operating system. This issue being tracked by Cisco Bug ID CSCut46961

Trust: 1.98

sources: NVD: CVE-2015-0701 // JVNDB: JVNDB-2015-002540 // BID: 74491 // VULHUB: VHN-78647

AFFECTED PRODUCTS

vendor:ciscomodel:unified computing system central softwarescope:eqversion:1.1_base

Trust: 1.6

vendor:ciscomodel:unified computing system central softwarescope:eqversion:1.2\(1e\)

Trust: 1.6

vendor:ciscomodel:unified computing system central softwarescope:eqversion:1.2\(1f\)

Trust: 1.6

vendor:ciscomodel:unified computing system central softwarescope:eqversion:1.0_base

Trust: 1.6

vendor:ciscomodel:unified computing system central softwarescope:eqversion:1.2\(1a\)

Trust: 1.6

vendor:ciscomodel:unified computing system central softwarescope:eqversion:1.2\(1d\)

Trust: 1.6

vendor:ciscomodel:unified computing system central software 1.2scope: - version: -

Trust: 1.2

vendor:ciscomodel:unified computing system central softwarescope:lteversion:1.2

Trust: 0.8

vendor:extremenetworksmodel:wireless apscope:eqversion:396510.1.1

Trust: 0.3

vendor:extremenetworksmodel:wireless apscope:eqversion:393510.1.1

Trust: 0.3

vendor:extremenetworksmodel:wireless apscope:eqversion:386510.1.1

Trust: 0.3

vendor:extremenetworksmodel:wireless apscope:eqversion:382510.1.1

Trust: 0.3

vendor:extremenetworksmodel:wireless apscope:eqversion:380510.1.1

Trust: 0.3

vendor:extremenetworksmodel:wireless apscope:eqversion:380110.1.1

Trust: 0.3

vendor:extremenetworksmodel:wireless apscope:eqversion:371510.1.1

Trust: 0.3

vendor:extremenetworksmodel:extremexosscope:eqversion:0

Trust: 0.3

vendor:ciscomodel:unified computing system central softwarescope:eqversion:1.2

Trust: 0.3

vendor:ciscomodel:unified computing system central softwarescope:eqversion:1.1

Trust: 0.3

vendor:ciscomodel:unified computing system central softwarescope:eqversion:1.0

Trust: 0.3

vendor:extremenetworksmodel:wireless apscope:neversion:396510.11.1

Trust: 0.3

vendor:extremenetworksmodel:wireless apscope:neversion:396510.1.4

Trust: 0.3

vendor:extremenetworksmodel:wireless apscope:neversion:393510.11.1

Trust: 0.3

vendor:extremenetworksmodel:wireless apscope:neversion:393510.1.4

Trust: 0.3

vendor:extremenetworksmodel:wireless apscope:neversion:386510.11.1

Trust: 0.3

vendor:extremenetworksmodel:wireless apscope:neversion:386510.1.4

Trust: 0.3

vendor:extremenetworksmodel:wireless apscope:neversion:382510.11.1

Trust: 0.3

vendor:extremenetworksmodel:wireless apscope:neversion:382510.1.4

Trust: 0.3

vendor:extremenetworksmodel:wireless apscope:neversion:380510.11.1

Trust: 0.3

vendor:extremenetworksmodel:wireless apscope:neversion:380510.1.4

Trust: 0.3

vendor:extremenetworksmodel:wireless apscope:neversion:380110.11.1

Trust: 0.3

vendor:extremenetworksmodel:wireless apscope:neversion:380110.1.4

Trust: 0.3

vendor:extremenetworksmodel:wireless apscope:neversion:371510.11.1

Trust: 0.3

vendor:extremenetworksmodel:wireless apscope:neversion:371510.1.4

Trust: 0.3

sources: BID: 74491 // JVNDB: JVNDB-2015-002540 // CNNVD: CNNVD-201505-028 // NVD: CVE-2015-0701

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2015-0701
value: HIGH

Trust: 1.0

NVD: CVE-2015-0701
value: HIGH

Trust: 0.8

CNNVD: CNNVD-201505-028
value: CRITICAL

Trust: 0.6

VULHUB: VHN-78647
value: HIGH

Trust: 0.1

nvd@nist.gov: CVE-2015-0701
severity: HIGH
baseScore: 10.0
vectorString: AV:N/AC:L/AU:N/C:C/I:C/A:C
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 10.0
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

VULHUB: VHN-78647
severity: HIGH
baseScore: 10.0
vectorString: AV:N/AC:L/AU:N/C:C/I:C/A:C
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 10.0
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

sources: VULHUB: VHN-78647 // JVNDB: JVNDB-2015-002540 // CNNVD: CNNVD-201505-028 // NVD: CVE-2015-0701

PROBLEMTYPE DATA

problemtype:CWE-20

Trust: 1.9

sources: VULHUB: VHN-78647 // JVNDB: JVNDB-2015-002540 // NVD: CVE-2015-0701

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-201505-028

TYPE

input validation

Trust: 0.6

sources: CNNVD: CNNVD-201505-028

CONFIGURATIONS

sources: JVNDB: JVNDB-2015-002540

PATCH

title:cisco-sa-20150506-ucscurl:http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20150506-ucsc

Trust: 0.8

title:38591url:http://tools.cisco.com/security/center/viewAlert.x?alertId=38591

Trust: 0.8

sources: JVNDB: JVNDB-2015-002540

EXTERNAL IDS

db:NVDid:CVE-2015-0701

Trust: 2.8

db:BIDid:74491

Trust: 1.4

db:SECTRACKid:1032267

Trust: 1.1

db:JVNDBid:JVNDB-2015-002540

Trust: 0.8

db:CNNVDid:CNNVD-201505-028

Trust: 0.7

db:VULHUBid:VHN-78647

Trust: 0.1

sources: VULHUB: VHN-78647 // BID: 74491 // JVNDB: JVNDB-2015-002540 // CNNVD: CNNVD-201505-028 // NVD: CVE-2015-0701

REFERENCES

url:http://tools.cisco.com/security/center/content/ciscosecurityadvisory/cisco-sa-20150506-ucsc

Trust: 2.0

url:http://www.securityfocus.com/bid/74491

Trust: 1.1

url:http://www.securitytracker.com/id/1032267

Trust: 1.1

url:http://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2015-0701

Trust: 0.8

url:http://web.nvd.nist.gov/view/vuln/detail?vulnid=cve-2015-0701

Trust: 0.8

url:http://www.cisco.com/

Trust: 0.3

url:http://tools.cisco.com/security/center/viewalert.x?alertid=38591

Trust: 0.3

url:https://gtacknowledge.extremenetworks.com/articles/vulnerability_notice/vn-2016-002-openssl/?q=cve-2015-3197&l=en_us&fs=search&pn=1

Trust: 0.3

sources: VULHUB: VHN-78647 // BID: 74491 // JVNDB: JVNDB-2015-002540 // CNNVD: CNNVD-201505-028 // NVD: CVE-2015-0701

CREDITS

Cisco

Trust: 0.3

sources: BID: 74491

SOURCES

db:VULHUBid:VHN-78647
db:BIDid:74491
db:JVNDBid:JVNDB-2015-002540
db:CNNVDid:CNNVD-201505-028
db:NVDid:CVE-2015-0701

LAST UPDATE DATE

2025-04-13T20:46:30.695000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-78647date:2016-11-28T00:00:00
db:BIDid:74491date:2016-07-21T02:00:00
db:JVNDBid:JVNDB-2015-002540date:2015-05-08T00:00:00
db:CNNVDid:CNNVD-201505-028date:2015-05-08T00:00:00
db:NVDid:CVE-2015-0701date:2025-04-12T10:46:40.837

SOURCES RELEASE DATE

db:VULHUBid:VHN-78647date:2015-05-07T00:00:00
db:BIDid:74491date:2015-05-06T00:00:00
db:JVNDBid:JVNDB-2015-002540date:2015-05-08T00:00:00
db:CNNVDid:CNNVD-201505-028date:2015-05-07T00:00:00
db:NVDid:CVE-2015-0701date:2015-05-07T01:59:02.323