CVE Database
/

CVE-2018-0148

Back to search

CVE-2018-0148

Published: Feb 22, 2018

Modified: Dec 2, 2024

PUBLISHED

Description

A vulnerability in the web-based management interface of Cisco UCS Director Software and Cisco Integrated Management Controller (IMC) Supervisor Software could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack and perform arbitrary actions on an affected system. The vulnerability is due to insufficient CSRF protection by the web-based management interface of the affected software. An attacker could exploit this vulnerability by persuading a user of the affected interface to click a malicious link. A successful exploit could allow the attacker to perform arbitrary actions, via the user's web browser and with the user's privileges, on an affected system. Cisco Bug IDs: CSCvf71929.

VendorProductVersions

n/a

Cisco UCS Director and Cisco Integrated Management Controller Supervisor

affected
Cisco UCS Director and Cisco Integrated Management Controller Supervisor

Weaknesses (CWE)

References

103141
vdb-entry
x_refsource_BID
1040412
vdb-entry
x_refsource_SECTRACK

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now