What happened
A vulnerability in the web-based management interface of Cisco UCS Manager Software could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface. This vulnerability is due to insufficient validation of user-supplied input by the web-based management interface of an affected system. An attacker could exploit this vulnerability by injecting malicious data into specific pages of the interface. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information. To exploit this vulnerability, the attacker must be a member of the Administrator or AAA Administrator role.
Affected versions
Cisco Unified Computing System (Managed): 4.0(1a); 4.1(1d); 4.0(4f); 4.0(4c); 4.0(2b); 4.1(2a); 4.0(4a); 4.0(4e); 3.2(3p); 4.0(4h); 3.2(3d); 3.2(3l); 3.2(3o); 4.0(2a); 4.1(1c); 4.0(1b); 3.2(3j); 3.2(2e); 4.1(1e); 4.0(4d); 3.2(1d); 3.2(3i); 4.0(4b); 4.0(2e); 4.1(1a); 3.2(3h); 4.0(4g); 3.2(2c); 3.2(3k); 3.2(3g); 3.2(2b); 4.0(1d); 3.2(3a); 4.0(1c); 3.2(3e); 3.2(2d); 4.0(4i); 3.2(2f); 4.0(2d); 4.1(1b); 3.2(3n); 3.2(3b); 4.1(2b); 4.0(4k); 4.1(3a); 4.1(3b); 4.1(2c); 4.0(4l); 4.1(4a); 4.1(3c); 4.1(3d); 4.2(1c); 4.2(1d); 4.0(4m); 4.1(3e); 4.2(1f); 4.1(3f); 4.2(1i); 4.1(3h); 4.2(1k); 4.2(1l); 4.0(4n); 4.2(1m); 4.1(3i); 4.2(2a); 4.2(1n); 4.1(3j); 4.2(2c); 4.2(2d); 4.2(3b); 4.1(3k); 4.0(4o); 4.2(2e); 4.2(3d); 4.2(3e); 4.2(3g); 4.1(3l); 4.3(2b); 4.2(3h); 4.2(3i); 4.3(2c); 4.1(3m); 4.3(2e); 4.3(3a); 4.2(3j); 4.3(3c); 4.3(4a); 4.2(3k); 4.3(4b); 4.3(4c); 4.2(3l); 4.3(4d); 4.3(2f); 4.2(3m); 4.3(5a); 4.3(4e); 4.1(3n); 4.3(4f); 4.2(3n); 4.3(5c); 4.2(3o); 4.3(5d); 4.3(5e) Fixed: See vendor advisory.
Why it matters
Review the vendor advisory and exposure of the affected product to determine operational impact.
Detection & mitigation
- Apply vendor-provided updates or mitigations.
- Review affected product exposure and access logs.
Public PoC references
No public PoC reference has passed the current publication threshold.