Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2015-0599

Опубликовано: 03 фев. 2015
Источник: nvd
CVSS2: 4.3
EPSS Низкий

Описание

The web interface in Cisco Integrated Management Controller in Cisco Unified Computing System (UCS) on C-Series Rack Servers does not properly restrict use of IFRAME elements, which makes it easier for remote attackers to conduct clickjacking attacks and unspecified other attacks via a crafted web site, related to a "cross-frame scripting (XFS)" issue, aka Bug ID CSCuf50138.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:h:cisco:unified_computing_system:-:*:*:*:*:*:*:*

EPSS

Процентиль: 62%
0.00422
Низкий

4.3 Medium

CVSS2

Дефекты

CWE-254

Связанные уязвимости

github
больше 3 лет назад

The web interface in Cisco Integrated Management Controller in Cisco Unified Computing System (UCS) on C-Series Rack Servers does not properly restrict use of IFRAME elements, which makes it easier for remote attackers to conduct clickjacking attacks and unspecified other attacks via a crafted web site, related to a "cross-frame scripting (XFS)" issue, aka Bug ID CSCuf50138.

EPSS

Процентиль: 62%
0.00422
Низкий

4.3 Medium

CVSS2

Дефекты

CWE-254