Cisco UCS Manager Software Command Injection Vulnerabilities
TL;DR 📌
Multiple command injection vulnerabilities have been identified in Cisco UCS Manager Software, allowing authenticated attackers with administrative privileges to execute arbitrary commands on affected systems. The highest CVSS score for these vulnerabilities is 6.5, indicating a Medium severity level. Software updates are available to address these issues, but no workarounds exist.
What happened 🕵️♂️
Cisco has disclosed multiple vulnerabilities in the CLI and web-based management interface of Cisco UCS Manager Software. These vulnerabilities could allow an authenticated attacker with administrative privileges to perform command injection attacks, potentially leading to root-level access on the affected systems. The vulnerabilities stem from insufficient input validation of command arguments supplied by users.
Affected products 🖥️
The following Cisco products are affected if they are running Cisco UCS Manager Software:
- UCS 6300 Series Fabric Interconnects
- UCS 6400 Series Fabric Interconnects
- UCS 6500 Series Fabric Interconnects
- UCS X-Series Direct Fabric Interconnect 9108 100G
Fixed software 🔧
Upgrade to the first fixed release in your train (or later):
| Release / Product | First Fixed Release | Notes |
|---|---|---|
| 4.1 and earlier | Migrate to a fixed release. | |
| 4.2 | 4.2(3p) | |
| 4.3 | 4.3(6c) | |
| 6.0 | Not vulnerable. | |
| 1.0 | Initial public release. | |
| Cisco UCS Software | 4.2(3p) | 4.1 and earlier |
| Cisco UCS Software | 4.3(6c) | 4.3 |
Workarounds 🧯
There are no workarounds that address these vulnerabilities.
Risk in context 🎯
With a CVSS score of 6.5, these vulnerabilities are rated as Medium severity. Exploitation requires administrative access, which limits exposure but still poses a significant risk if an attacker gains such access. The vulnerabilities could allow for arbitrary command execution, potentially compromising system integrity.
Fast facts ⚡
- CVSS Score: 6.5 (Medium)
- Vulnerabilities: Command injection allowing root access.
- Affected Products: UCS 6300, 6400, 6500 Series, and UCS X-Series Direct Fabric Interconnect 9108 100G.
- Workarounds: None available.
- Fixed Software: Specific releases noted above.
For leadership 🧭
Executive summary. An authenticated administrator on Cisco UCS Manager can escalate to root on the fabric interconnects that control your UCS blade and rack infrastructure, turning a management-plane account into full system compromise. There’s no workaround, so this needs scheduling into the next maintenance window rather than immediate emergency action given the medium severity and admin-only access requirement.
Why it matters:
- The flaw sits in the CLI and web-based management interface of UCS Manager, the control plane for UCS 6300, 6400, 6500 Series and UCS X-Series Direct Fabric Interconnect 9108 100G hardware.
- Insufficient input validation of command arguments lets an already-authenticated admin escalate to root, meaning a compromised or malicious admin account becomes a full system takeover rather than a contained privilege.
- Fabric interconnects manage server profiles, network and storage connectivity for an entire UCS domain, so root access there affects every chassis and blade under that manager.
- No workaround exists, so exposure persists on any UCS Manager instance running 4.1 or earlier, or pre-4.2(3p)/4.3(6c) code, until it is patched.
Now / Next / Later:
- Now: Identify every UCS Manager instance and fabric interconnect (6300/6400/6500 Series, UCS X-Series 9108 100G) still on 4.1 or earlier releases, or on 4.2/4.3 trains prior to the fixed builds, and review who holds administrative accounts on them.
- Next: Upgrade UCS Manager Software to 4.2(3p) or 4.3(6c) as appropriate for each fabric interconnect train during the next scheduled maintenance window; migrate any 4.1-or-earlier deployments to a fixed release entirely.
- Later: Tighten and audit administrative access to UCS Manager’s CLI and web interface as a matter of course, since this class of vulnerability requires admin credentials to exploit and reducing standing admin access limits future risk from similar command-injection issues.