imPC@ndo IT

Tracker / CVE-2013-1182

CVE-2013-1182

High 9.3

The login page in the Web Console in the Manager component in Cisco Unified Computing System (UCS) before 1.0(2h), 1.1 before 1.1(1j), and 1.3(x) allows remote attackers to bypass LDAP authentication via a malformed request, aka Bug ID CSCtc91207.

Affected products and versions

cisco unified_computing_system_6120xp_fabric_interconnect
cisco unified_computing_system_6140xp_fabric_interconnect
cisco unified_computing_system_6248up_fabric_interconnect
cisco unified_computing_system_6296up_fabric_interconnect
cisco unified_computing_system_infrastructure_and_unified_computing_system_software
cisco unified_computing_system_infrastructure_and_unified_computing_system_software · … → 1.0
cisco unified_computing_system_integrated_management_controller

Analysis

This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.

References