MEDIUM · 6.8

CVE-2015-0633

The Integrated Management Controller (IMC) in Cisco Unified Computing System (UCS) 1.4(7h) and earlier on C-Series servers allows remote attackers to bypass intended access restrictions by sending cra...

Vulnerability Description

The Integrated Management Controller (IMC) in Cisco Unified Computing System (UCS) 1.4(7h) and earlier on C-Series servers allows remote attackers to bypass intended access restrictions by sending crafted DHCP response packets on the local network, aka Bug ID CSCuf52876.

CVSS Score

6.8

MEDIUM

AV:A/AC:L/Au:N/C:N/I:P/A:C
Confidentiality
NONE
Integrity
PARTIAL
Availability
COMPLETE

Affected Products

VendorProductVersions
CiscoUnified Computing System1.4
CiscoC200 M1All versions
CiscoC200 M2All versions
CiscoC210 M2All versions
CiscoC22 M3All versions
CiscoC220 M3All versions
CiscoC220 M4All versions
CiscoC24 M3All versions
CiscoC240 M3All versions
CiscoC240 M4All versions
CiscoC250 M1All versions
CiscoC250 M2All versions
CiscoC260 M2All versions
CiscoC3160All versions
CiscoC420 M2All versions
CiscoC420 M3All versions
CiscoC460 M1All versions
CiscoC460 M2All versions
CiscoC460 M4All versions

Related Weaknesses (CWE)

References

FAQ

What is CVE-2015-0633?

CVE-2015-0633 is a vulnerability with a CVSS score of 6.8 (MEDIUM). The Integrated Management Controller (IMC) in Cisco Unified Computing System (UCS) 1.4(7h) and earlier on C-Series servers allows remote attackers to bypass intended access restrictions by sending cra...

How severe is CVE-2015-0633?

CVE-2015-0633 has been rated MEDIUM with a CVSS base score of 6.8/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2015-0633?

Check the references section above for vendor advisories and patch information. Affected products include: Cisco Unified Computing System, Cisco C200 M1, Cisco C200 M2, Cisco C210 M2, Cisco C22 M3.