ID

VAR-201511-0010


CVE

CVE-2015-6355


TITLE

Operates on the blade server Cisco Unified Computing System of Web Vulnerability in which important version information is obtained in the interface

Trust: 0.8

sources: JVNDB: JVNDB-2015-005732

DESCRIPTION

The web interface in Cisco Unified Computing System (UCS) 2.2(5b)A on blade servers allows remote attackers to obtain potentially sensitive version information by visiting an unspecified URL, aka Bug ID CSCuw87226. Vendors have confirmed this vulnerability Bug ID CSCuw87226 It is released as.Unspecified by a third party URL By accessing, important version information may be obtained. Cisco Unified Computing System is prone to a remote information-disclosure vulnerability. Successful exploits may allow an attacker to obtain sensitive information that may lead to further attacks. This issue is tracked by Cisco Bug ID CSCuw87226. The system integrates network, computing and virtualization resources into one platform by extensively adopting virtualization technology. A security vulnerability exists in Cisco UCS Release 2.2(5b)A on Blade Server

Trust: 1.98

sources: NVD: CVE-2015-6355 // JVNDB: JVNDB-2015-005732 // BID: 77401 // VULHUB: VHN-84316

AFFECTED PRODUCTS

vendor:ciscomodel:unified computing systemscope:eqversion:2.2\(5b\)a

Trust: 1.6

vendor:ciscomodel:unified computing system softwarescope:eqversion:2.2(5b)a

Trust: 0.8

vendor:ciscomodel:unified computing system 2.2 ascope: - version: -

Trust: 0.3

sources: BID: 77401 // JVNDB: JVNDB-2015-005732 // CNNVD: CNNVD-201511-031 // NVD: CVE-2015-6355

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2015-6355
value: MEDIUM

Trust: 1.0

NVD: CVE-2015-6355
value: MEDIUM

Trust: 0.8

CNNVD: CNNVD-201511-031
value: MEDIUM

Trust: 0.6

VULHUB: VHN-84316
value: MEDIUM

Trust: 0.1

nvd@nist.gov: CVE-2015-6355
severity: MEDIUM
baseScore: 5.0
vectorString: AV:N/AC:L/AU:N/C:P/I:N/A:N
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 10.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

VULHUB: VHN-84316
severity: MEDIUM
baseScore: 5.0
vectorString: AV:N/AC:L/AU:N/C:P/I:N/A:N
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 10.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

sources: VULHUB: VHN-84316 // JVNDB: JVNDB-2015-005732 // CNNVD: CNNVD-201511-031 // NVD: CVE-2015-6355

PROBLEMTYPE DATA

problemtype:CWE-200

Trust: 1.9

sources: VULHUB: VHN-84316 // JVNDB: JVNDB-2015-005732 // NVD: CVE-2015-6355

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-201511-031

TYPE

information disclosure

Trust: 0.6

sources: CNNVD: CNNVD-201511-031

CONFIGURATIONS

sources: JVNDB: JVNDB-2015-005732

PATCH

title:cisco-sa-20151102-ucsurl:http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20151102-ucs

Trust: 0.8

title:cisco-sa-20151102-ucsurl:http://www.cisco.com/cisco/web/support/JP/113/1136/1136187_cisco-sa-20151102-ucs-j.html

Trust: 0.8

sources: JVNDB: JVNDB-2015-005732

EXTERNAL IDS

db:NVDid:CVE-2015-6355

Trust: 2.8

db:SECTRACKid:1034042

Trust: 1.1

db:BIDid:77401

Trust: 1.0

db:JVNDBid:JVNDB-2015-005732

Trust: 0.8

db:CNNVDid:CNNVD-201511-031

Trust: 0.7

db:VULHUBid:VHN-84316

Trust: 0.1

sources: VULHUB: VHN-84316 // BID: 77401 // JVNDB: JVNDB-2015-005732 // CNNVD: CNNVD-201511-031 // NVD: CVE-2015-6355

REFERENCES

url:http://tools.cisco.com/security/center/content/ciscosecurityadvisory/cisco-sa-20151102-ucs

Trust: 2.0

url:http://www.securitytracker.com/id/1034042

Trust: 1.1

url:http://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2015-6355

Trust: 0.8

url:http://web.nvd.nist.gov/view/vuln/detail?vulnid=cve-2015-6355

Trust: 0.8

url:http://www.securityfocus.com/bid/77401

Trust: 0.6

url:http://www.cisco.com/

Trust: 0.3

sources: VULHUB: VHN-84316 // BID: 77401 // JVNDB: JVNDB-2015-005732 // CNNVD: CNNVD-201511-031 // NVD: CVE-2015-6355

CREDITS

Cisco

Trust: 0.9

sources: BID: 77401 // CNNVD: CNNVD-201511-031

SOURCES

db:VULHUBid:VHN-84316
db:BIDid:77401
db:JVNDBid:JVNDB-2015-005732
db:CNNVDid:CNNVD-201511-031
db:NVDid:CVE-2015-6355

LAST UPDATE DATE

2024-11-23T21:54:48.562000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-84316date:2018-10-30T00:00:00
db:BIDid:77401date:2015-11-02T00:00:00
db:JVNDBid:JVNDB-2015-005732date:2015-11-05T00:00:00
db:CNNVDid:CNNVD-201511-031date:2015-11-05T00:00:00
db:NVDid:CVE-2015-6355date:2024-11-21T02:34:50.593

SOURCES RELEASE DATE

db:VULHUBid:VHN-84316date:2015-11-04T00:00:00
db:BIDid:77401date:2015-11-02T00:00:00
db:JVNDBid:JVNDB-2015-005732date:2015-11-05T00:00:00
db:CNNVDid:CNNVD-201511-031date:2015-11-04T00:00:00
db:NVDid:CVE-2015-6355date:2015-11-04T03:59:09.340