imPC@ndo IT

Tracker / CVE-2013-1185

CVE-2013-1185

High 9.3

The web interface in the Manager component in Cisco Unified Computing System (UCS) 1.x and 2.x before 2.0(2m) allows remote attackers to obtain sensitive information by reading a (1) technical-support bundle file or (2) on-device configuration backup, aka Bug ID CSCtq86543.

Affected products and versions

cisco unified_computing_system_6120xp_fabric_interconnect
cisco unified_computing_system_6140xp_fabric_interconnect
cisco unified_computing_system_6248up_fabric_interconnect
cisco unified_computing_system_6296up_fabric_interconnect
cisco unified_computing_system_infrastructure_and_unified_computing_system_software
cisco unified_computing_system_integrated_management_controller

Analysis

This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.

References