The login page in the Web Console in the Manager component in Cisco Unified Computing System (UCS) before 1.0(2h), 1.1 before 1.1(1j), and 1.3(x) allows remote attackers to bypass LDAP authentication via a malformed request, aka Bug ID CSCtc91207.
References
Link | Resource |
---|---|
http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20130424-ucsmulti | Vendor Advisory |
Configurations
Configuration 1 (hide)
AND |
|
Information
Published : 2013-04-25 03:55
Updated : 2013-04-25 03:55
NVD link : CVE-2013-1182
Mitre link : CVE-2013-1182
JSON object : View
CWE
CWE-264
Permissions, Privileges, and Access Controls
Products Affected
cisco
- unified_computing_system_6296up_fabric_interconnect
- unified_computing_system_infrastructure_and_unified_computing_system_software
- unified_computing_system_integrated_management_controller
- unified_computing_system_6248up_fabric_interconnect
- unified_computing_system_6140xp_fabric_interconnect
- unified_computing_system_6120xp_fabric_interconnect