CVE-2015-6435 (CNNVD-201601-601)
中文标题:
Cisco Unified Computing System Manager和FX-OS for Firepower 9000 Series 安全漏洞
英文标题:
An unspecified CGI script in Cisco FX-OS before 1.1.2 on Firepower 9000 devices and Cisco Unified Co...
漏洞描述
中文描述:
Cisco Unified Computing System Manager和Cisco FX-OS on Firepower 9000都是美国思科(Cisco)公司的产品。前者是一套内嵌设备管理软件,它能将思科统一计算系统作为单一、高度可用的逻辑实体,从端到端加以管理,后者是一套运行于9000系列防火墙设备中的操作系统。 Cisco UCS Manager和FX-OS for Firepower 9000 Series中的CGI脚本存在安全漏洞。远程攻击者可通过发送特制的HTTP请求利用该漏洞执行任意shell命令。以下产品及版本受到影响:Cisco UCS Manager 2.2(4b)之前版本,2.2(5a)之前2.2(5)版本,3.0(2e)之前3.0版本,FX-OS for Firepower 9000 Series 1.1.2之前版本。
英文描述:
An unspecified CGI script in Cisco FX-OS before 1.1.2 on Firepower 9000 devices and Cisco Unified Computing System (UCS) Manager before 2.2(4b), 2.2(5) before 2.2(5a), and 3.0 before 3.0(2e) allows remote attackers to execute arbitrary shell commands via a crafted HTTP request, aka Bug ID CSCur90888.
CWE类型:
标签:
受影响产品
| 厂商 | 产品 | 版本 | 版本范围 | 平台 | CPE |
|---|---|---|---|---|---|
| cisco | firepower_extensible_operating_system | 1.1\(1.86\) | - | - |
cpe:2.3:o:cisco:firepower_extensible_operating_system:1.1\(1.86\):*:*:*:*:*:*:*
|
| cisco | firepower_extensible_operating_system | 1.1\(1.160\) | - | - |
cpe:2.3:o:cisco:firepower_extensible_operating_system:1.1\(1.160\):*:*:*:*:*:*:*
|
| cisco | firepower_extensible_operating_system | 1.1.1 | - | - |
cpe:2.3:o:cisco:firepower_extensible_operating_system:1.1.1:*:*:*:*:*:*:*
|
| cisco | unified_computing_system | 1.0\(2k\) | - | - |
cpe:2.3:a:cisco:unified_computing_system:1.0\(2k\):*:*:*:*:*:*:*
|
| cisco | unified_computing_system | 1.0_base | - | - |
cpe:2.3:a:cisco:unified_computing_system:1.0_base:*:*:*:*:*:*:*
|
| cisco | unified_computing_system | 1.1\(1m\) | - | - |
cpe:2.3:a:cisco:unified_computing_system:1.1\(1m\):*:*:*:*:*:*:*
|
| cisco | unified_computing_system | 1.1_base | - | - |
cpe:2.3:a:cisco:unified_computing_system:1.1_base:*:*:*:*:*:*:*
|
| cisco | unified_computing_system | 1.2\(1d\) | - | - |
cpe:2.3:a:cisco:unified_computing_system:1.2\(1d\):*:*:*:*:*:*:*
|
| cisco | unified_computing_system | 1.2_base | - | - |
cpe:2.3:a:cisco:unified_computing_system:1.2_base:*:*:*:*:*:*:*
|
| cisco | unified_computing_system | 1.3\(1c\) | - | - |
cpe:2.3:a:cisco:unified_computing_system:1.3\(1c\):*:*:*:*:*:*:*
|
| cisco | unified_computing_system | 1.3\(1m\) | - | - |
cpe:2.3:a:cisco:unified_computing_system:1.3\(1m\):*:*:*:*:*:*:*
|
| cisco | unified_computing_system | 1.3\(1n\) | - | - |
cpe:2.3:a:cisco:unified_computing_system:1.3\(1n\):*:*:*:*:*:*:*
|
| cisco | unified_computing_system | 1.3\(1o\) | - | - |
cpe:2.3:a:cisco:unified_computing_system:1.3\(1o\):*:*:*:*:*:*:*
|
| cisco | unified_computing_system | 1.3\(1p\) | - | - |
cpe:2.3:a:cisco:unified_computing_system:1.3\(1p\):*:*:*:*:*:*:*
|
| cisco | unified_computing_system | 1.3\(1q\) | - | - |
cpe:2.3:a:cisco:unified_computing_system:1.3\(1q\):*:*:*:*:*:*:*
|
| cisco | unified_computing_system | 1.3\(1t\) | - | - |
cpe:2.3:a:cisco:unified_computing_system:1.3\(1t\):*:*:*:*:*:*:*
|
| cisco | unified_computing_system | 1.3\(1w\) | - | - |
cpe:2.3:a:cisco:unified_computing_system:1.3\(1w\):*:*:*:*:*:*:*
|
| cisco | unified_computing_system | 1.3\(1y\) | - | - |
cpe:2.3:a:cisco:unified_computing_system:1.3\(1y\):*:*:*:*:*:*:*
|
| cisco | unified_computing_system | 1.3_base | - | - |
cpe:2.3:a:cisco:unified_computing_system:1.3_base:*:*:*:*:*:*:*
|
| cisco | unified_computing_system | 1.4\(1i\) | - | - |
cpe:2.3:a:cisco:unified_computing_system:1.4\(1i\):*:*:*:*:*:*:*
|
| cisco | unified_computing_system | 1.4\(1j\) | - | - |
cpe:2.3:a:cisco:unified_computing_system:1.4\(1j\):*:*:*:*:*:*:*
|
| cisco | unified_computing_system | 1.4\(1m\) | - | - |
cpe:2.3:a:cisco:unified_computing_system:1.4\(1m\):*:*:*:*:*:*:*
|
| cisco | unified_computing_system | 1.4\(3i\) | - | - |
cpe:2.3:a:cisco:unified_computing_system:1.4\(3i\):*:*:*:*:*:*:*
|
| cisco | unified_computing_system | 1.4\(3l\) | - | - |
cpe:2.3:a:cisco:unified_computing_system:1.4\(3l\):*:*:*:*:*:*:*
|
| cisco | unified_computing_system | 1.4\(3m\) | - | - |
cpe:2.3:a:cisco:unified_computing_system:1.4\(3m\):*:*:*:*:*:*:*
|
| cisco | unified_computing_system | 1.4\(3q\) | - | - |
cpe:2.3:a:cisco:unified_computing_system:1.4\(3q\):*:*:*:*:*:*:*
|
| cisco | unified_computing_system | 1.4\(3s\) | - | - |
cpe:2.3:a:cisco:unified_computing_system:1.4\(3s\):*:*:*:*:*:*:*
|
| cisco | unified_computing_system | 1.4\(3u\) | - | - |
cpe:2.3:a:cisco:unified_computing_system:1.4\(3u\):*:*:*:*:*:*:*
|
| cisco | unified_computing_system | 1.4\(3y\) | - | - |
cpe:2.3:a:cisco:unified_computing_system:1.4\(3y\):*:*:*:*:*:*:*
|
| cisco | unified_computing_system | 1.4\(4f\) | - | - |
cpe:2.3:a:cisco:unified_computing_system:1.4\(4f\):*:*:*:*:*:*:*
|
| cisco | unified_computing_system | 1.4\(4g\) | - | - |
cpe:2.3:a:cisco:unified_computing_system:1.4\(4g\):*:*:*:*:*:*:*
|
| cisco | unified_computing_system | 1.4\(4i\) | - | - |
cpe:2.3:a:cisco:unified_computing_system:1.4\(4i\):*:*:*:*:*:*:*
|
| cisco | unified_computing_system | 1.4\(4j\) | - | - |
cpe:2.3:a:cisco:unified_computing_system:1.4\(4j\):*:*:*:*:*:*:*
|
| cisco | unified_computing_system | 1.4\(4k\) | - | - |
cpe:2.3:a:cisco:unified_computing_system:1.4\(4k\):*:*:*:*:*:*:*
|
| cisco | unified_computing_system | 1.4_base | - | - |
cpe:2.3:a:cisco:unified_computing_system:1.4_base:*:*:*:*:*:*:*
|
| cisco | unified_computing_system | 2.0\(1m\) | - | - |
cpe:2.3:a:cisco:unified_computing_system:2.0\(1m\):*:*:*:*:*:*:*
|
| cisco | unified_computing_system | 2.0\(1q\) | - | - |
cpe:2.3:a:cisco:unified_computing_system:2.0\(1q\):*:*:*:*:*:*:*
|
| cisco | unified_computing_system | 2.0\(1s\) | - | - |
cpe:2.3:a:cisco:unified_computing_system:2.0\(1s\):*:*:*:*:*:*:*
|
| cisco | unified_computing_system | 2.0\(1t\) | - | - |
cpe:2.3:a:cisco:unified_computing_system:2.0\(1t\):*:*:*:*:*:*:*
|
| cisco | unified_computing_system | 2.0\(1w\) | - | - |
cpe:2.3:a:cisco:unified_computing_system:2.0\(1w\):*:*:*:*:*:*:*
|
| cisco | unified_computing_system | 2.0\(1x\) | - | - |
cpe:2.3:a:cisco:unified_computing_system:2.0\(1x\):*:*:*:*:*:*:*
|
| cisco | unified_computing_system | 2.0\(2m\) | - | - |
cpe:2.3:a:cisco:unified_computing_system:2.0\(2m\):*:*:*:*:*:*:*
|
| cisco | unified_computing_system | 2.0\(2q\) | - | - |
cpe:2.3:a:cisco:unified_computing_system:2.0\(2q\):*:*:*:*:*:*:*
|
| cisco | unified_computing_system | 2.0\(2r\) | - | - |
cpe:2.3:a:cisco:unified_computing_system:2.0\(2r\):*:*:*:*:*:*:*
|
| cisco | unified_computing_system | 2.0\(3a\) | - | - |
cpe:2.3:a:cisco:unified_computing_system:2.0\(3a\):*:*:*:*:*:*:*
|
| cisco | unified_computing_system | 2.0\(3b\) | - | - |
cpe:2.3:a:cisco:unified_computing_system:2.0\(3b\):*:*:*:*:*:*:*
|
| cisco | unified_computing_system | 2.0\(3c\) | - | - |
cpe:2.3:a:cisco:unified_computing_system:2.0\(3c\):*:*:*:*:*:*:*
|
| cisco | unified_computing_system | 2.0\(4a\) | - | - |
cpe:2.3:a:cisco:unified_computing_system:2.0\(4a\):*:*:*:*:*:*:*
|
| cisco | unified_computing_system | 2.0\(4b\) | - | - |
cpe:2.3:a:cisco:unified_computing_system:2.0\(4b\):*:*:*:*:*:*:*
|
| cisco | unified_computing_system | 2.0\(4d\) | - | - |
cpe:2.3:a:cisco:unified_computing_system:2.0\(4d\):*:*:*:*:*:*:*
|
| cisco | unified_computing_system | 2.0\(5a\) | - | - |
cpe:2.3:a:cisco:unified_computing_system:2.0\(5a\):*:*:*:*:*:*:*
|
| cisco | unified_computing_system | 2.0\(5b\) | - | - |
cpe:2.3:a:cisco:unified_computing_system:2.0\(5b\):*:*:*:*:*:*:*
|
| cisco | unified_computing_system | 2.0\(5c\) | - | - |
cpe:2.3:a:cisco:unified_computing_system:2.0\(5c\):*:*:*:*:*:*:*
|
| cisco | unified_computing_system | 2.0_base | - | - |
cpe:2.3:a:cisco:unified_computing_system:2.0_base:*:*:*:*:*:*:*
|
| cisco | unified_computing_system | 2.1\(1a\) | - | - |
cpe:2.3:a:cisco:unified_computing_system:2.1\(1a\):*:*:*:*:*:*:*
|
| cisco | unified_computing_system | 2.1\(1b\) | - | - |
cpe:2.3:a:cisco:unified_computing_system:2.1\(1b\):*:*:*:*:*:*:*
|
| cisco | unified_computing_system | 2.1\(1d\) | - | - |
cpe:2.3:a:cisco:unified_computing_system:2.1\(1d\):*:*:*:*:*:*:*
|
| cisco | unified_computing_system | 2.1\(1e\) | - | - |
cpe:2.3:a:cisco:unified_computing_system:2.1\(1e\):*:*:*:*:*:*:*
|
| cisco | unified_computing_system | 2.1\(1f\) | - | - |
cpe:2.3:a:cisco:unified_computing_system:2.1\(1f\):*:*:*:*:*:*:*
|
| cisco | unified_computing_system | 2.1\(2a\) | - | - |
cpe:2.3:a:cisco:unified_computing_system:2.1\(2a\):*:*:*:*:*:*:*
|
| cisco | unified_computing_system | 2.1_base | - | - |
cpe:2.3:a:cisco:unified_computing_system:2.1_base:*:*:*:*:*:*:*
|
| cisco | unified_computing_system | 2.2\(1b\) | - | - |
cpe:2.3:a:cisco:unified_computing_system:2.2\(1b\):*:*:*:*:*:*:*
|
| cisco | unified_computing_system | 2.2\(1c\) | - | - |
cpe:2.3:a:cisco:unified_computing_system:2.2\(1c\):*:*:*:*:*:*:*
|
| cisco | unified_computing_system | 2.2\(1d\) | - | - |
cpe:2.3:a:cisco:unified_computing_system:2.2\(1d\):*:*:*:*:*:*:*
|
| cisco | unified_computing_system | 2.2\(1e\) | - | - |
cpe:2.3:a:cisco:unified_computing_system:2.2\(1e\):*:*:*:*:*:*:*
|
| cisco | unified_computing_system | 2.2\(1f\) | - | - |
cpe:2.3:a:cisco:unified_computing_system:2.2\(1f\):*:*:*:*:*:*:*
|
| cisco | unified_computing_system | 2.2\(1g\) | - | - |
cpe:2.3:a:cisco:unified_computing_system:2.2\(1g\):*:*:*:*:*:*:*
|
| cisco | unified_computing_system | 2.2\(1h\) | - | - |
cpe:2.3:a:cisco:unified_computing_system:2.2\(1h\):*:*:*:*:*:*:*
|
| cisco | unified_computing_system | 2.2\(2c\) | - | - |
cpe:2.3:a:cisco:unified_computing_system:2.2\(2c\):*:*:*:*:*:*:*
|
| cisco | unified_computing_system | 2.2\(2c\)a | - | - |
cpe:2.3:a:cisco:unified_computing_system:2.2\(2c\)a:*:*:*:*:*:*:*
|
| cisco | unified_computing_system | 2.2\(3a\) | - | - |
cpe:2.3:a:cisco:unified_computing_system:2.2\(3a\):*:*:*:*:*:*:*
|
| cisco | unified_computing_system | 2.2\(3b\) | - | - |
cpe:2.3:a:cisco:unified_computing_system:2.2\(3b\):*:*:*:*:*:*:*
|
| cisco | unified_computing_system | 2.2\(3c\) | - | - |
cpe:2.3:a:cisco:unified_computing_system:2.2\(3c\):*:*:*:*:*:*:*
|
| cisco | unified_computing_system | 2.2\(3d\) | - | - |
cpe:2.3:a:cisco:unified_computing_system:2.2\(3d\):*:*:*:*:*:*:*
|
| cisco | unified_computing_system | 2.2\(3e\) | - | - |
cpe:2.3:a:cisco:unified_computing_system:2.2\(3e\):*:*:*:*:*:*:*
|
| cisco | unified_computing_system | 2.2\(3f\) | - | - |
cpe:2.3:a:cisco:unified_computing_system:2.2\(3f\):*:*:*:*:*:*:*
|
| cisco | unified_computing_system | 2.2\(3g\) | - | - |
cpe:2.3:a:cisco:unified_computing_system:2.2\(3g\):*:*:*:*:*:*:*
|
| cisco | unified_computing_system | 2.2\(4b\) | - | - |
cpe:2.3:a:cisco:unified_computing_system:2.2\(4b\):*:*:*:*:*:*:*
|
| cisco | unified_computing_system | 2.2\(4c\) | - | - |
cpe:2.3:a:cisco:unified_computing_system:2.2\(4c\):*:*:*:*:*:*:*
|
| cisco | unified_computing_system | 2.2\(5a\) | - | - |
cpe:2.3:a:cisco:unified_computing_system:2.2\(5a\):*:*:*:*:*:*:*
|
| cisco | unified_computing_system | 2.2_base | - | - |
cpe:2.3:a:cisco:unified_computing_system:2.2_base:*:*:*:*:*:*:*
|
| cisco | unified_computing_system | 3.0\(1c\) | - | - |
cpe:2.3:a:cisco:unified_computing_system:3.0\(1c\):*:*:*:*:*:*:*
|
| cisco | unified_computing_system | 3.0\(1d\) | - | - |
cpe:2.3:a:cisco:unified_computing_system:3.0\(1d\):*:*:*:*:*:*:*
|
| cisco | unified_computing_system | 3.0\(1e\) | - | - |
cpe:2.3:a:cisco:unified_computing_system:3.0\(1e\):*:*:*:*:*:*:*
|
| cisco | unified_computing_system | 3.0\(2c\) | - | - |
cpe:2.3:a:cisco:unified_computing_system:3.0\(2c\):*:*:*:*:*:*:*
|
| cisco | unified_computing_system | 3.0\(2d\) | - | - |
cpe:2.3:a:cisco:unified_computing_system:3.0\(2d\):*:*:*:*:*:*:*
|
解决方案
中文解决方案:
英文解决方案:
临时解决方案:
CVSS评分详情
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
时间信息
利用信息
数据源详情
| 数据源 | 记录ID | 版本 | 提取时间 |
|---|---|---|---|
| CVE | cve_CVE-2015-6435 |
2025-11-11 15:18:59 | 2025-11-11 07:34:07 |
| NVD | nvd_CVE-2015-6435 |
2025-11-11 14:54:53 | 2025-11-11 07:42:48 |
| CNNVD | cnnvd_CNNVD-201601-601 |
2025-11-11 15:09:38 | 2025-11-11 07:52:22 |
版本与语言
安全公告
变更历史
查看详细变更
- vulnerability_type: 未提取 -> 授权问题
- cnnvd_id: 未提取 -> CNNVD-201601-601
- data_sources: ['cve', 'nvd'] -> ['cnnvd', 'cve', 'nvd']
查看详细变更
- severity: SeverityLevel.MEDIUM -> SeverityLevel.CRITICAL
- cvss_score: 未提取 -> 9.8
- cvss_vector: NOT_EXTRACTED -> CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- cvss_version: NOT_EXTRACTED -> 3.0
- affected_products_count: 0 -> 86
- data_sources: ['cve'] -> ['cve', 'nvd']