Cisco UCS Manager Software Stored Cross-Site Scripting Vulnerability
TL;DR 📌
A stored cross-site scripting (XSS) vulnerability has been identified in Cisco UCS Manager Software, allowing authenticated attackers to inject malicious scripts. This could lead to unauthorized access to sensitive information. The highest CVSS score is 5.4, indicating a medium severity risk. No workarounds are available, but Cisco has released fixed software versions.
What happened 🕵️♂️
A vulnerability in the web-based management interface of Cisco UCS Manager Software allows an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack. This vulnerability arises from insufficient validation of user-supplied input, enabling attackers to inject malicious data into specific pages. Successful exploitation could allow attackers to execute arbitrary scripts or access sensitive browser-based information. To exploit this vulnerability, the attacker must hold an Administrator or AAA Administrator role.
Affected products 🖥️
The following Cisco products are affected if they are running Cisco UCS Manager Software:
- UCS 6300 Series Fabric Interconnects
- UCS 6400 Series Fabric Interconnects
- UCS 6500 Series Fabric Interconnects
- UCS X-Series Direct Fabric Interconnect 9108 100G
Fixed software 🔧
Upgrade to the first fixed release in your train (or later):
| Release / Product | First Fixed Release | Notes |
|---|---|---|
| 4.1 and earlier | Migrate to a fixed release. | |
| 4.2 | 4.2(3p) | |
| 4.3 | 4.3(6a) | |
| 6.0 | Not vulnerable. | |
| 1.0 | Initial public release. | |
| Cisco UCS Software | 4.2(3p) | 4.1 and earlier |
| Cisco UCS Software | 4.3(6a) | 4.3 |
Workarounds 🧯
There are no workarounds available to address this vulnerability.
Risk in context 🎯
With a CVSS score of 5.4, this vulnerability is rated as medium severity. The risk is primarily driven by the requirement for authenticated access, limiting exposure to users with Administrator roles. However, the potential for sensitive information exposure remains a concern. Organizations should prioritize patching to mitigate this risk.
Fast facts ⚡
- Vulnerability Type: Stored Cross-Site Scripting (XSS)
- CVSS Score: 5.4 (Medium)
- Exploitation: Requires authenticated access (Administrator role)
- Workarounds: None available
- Fixed Software: Available for specific releases
For leadership 🧭
Executive summary. A privileged UCS Manager account can be used to plant malicious script in the fabric interconnect’s management interface, which then runs against other administrators who view the same page. It’s rated medium severity and there’s no workaround, so it should be scheduled into the next routine patch cycle rather than treated as an emergency.
Why it matters:
- The attack path runs through the Cisco UCS Manager web interface used to administer 6300, 6400 and 6500 Series Fabric Interconnects and the X-Series Direct 9108 100G Fabric Interconnect.
- Because the script is stored, it can execute against any administrator who later opens the affected page, potentially exposing session or browser-based data even though the original attacker already needed high privileges.
- There is no workaround, so exposure persists until the fabric interconnect’s UCS Manager software is upgraded to a fixed release.
- Exploitation requires an existing Administrator or AAA Administrator account, so the immediate risk is tied to how tightly those privileged roles are controlled and audited.
Now / Next / Later:
- Now: Review who currently holds Administrator or AAA Administrator roles on each UCS Manager instance and confirm those accounts are still needed and properly controlled.
- Next: Upgrade affected fabric interconnects to the first fixed release for their train — 4.2(3p) for 4.2 and earlier trains, or 4.3(6a) for 4.3 — during the next scheduled maintenance window.
- Later: Build UCS Manager software version checks into routine patch management so future fixed releases for the fabric interconnect line are applied on a predictable schedule.