CVE-2015-6435

EUVD-2015-6376
An unspecified CGI script in Cisco FX-OS before 1.1.2 on Firepower 9000 devices and Cisco Unified Computing System (UCS) Manager before 2.2(4b), 2.2(5) before 2.2(5a), and 3.0 before 3.0(2e) allows remote attackers to execute arbitrary shell commands via a crafted HTTP request, aka Bug ID CSCur90888.
OS Command Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 94%
Affected Products (NVD)
VendorProductVersion
ciscofirepower_extensible_operating_system
1.1\(1.86\)
ciscofirepower_extensible_operating_system
1.1\(1.160\)
ciscofirepower_extensible_operating_system
1.1.1
ciscounified_computing_system
1.0\(2k\)
ciscounified_computing_system
1.0_base:_base
ciscounified_computing_system
1.1\(1m\)
ciscounified_computing_system
1.1_base:_base
ciscounified_computing_system
1.2\(1d\)
ciscounified_computing_system
1.2_base:_base
ciscounified_computing_system
1.3\(1c\)
ciscounified_computing_system
1.3\(1m\)
ciscounified_computing_system
1.3\(1n\)
ciscounified_computing_system
1.3\(1o\)
ciscounified_computing_system
1.3\(1p\)
ciscounified_computing_system
1.3\(1q\)
ciscounified_computing_system
1.3\(1t\)
ciscounified_computing_system
1.3\(1w\)
ciscounified_computing_system
1.3\(1y\)
ciscounified_computing_system
1.3_base:_base
ciscounified_computing_system
1.4\(1i\)
ciscounified_computing_system
1.4\(1j\)
ciscounified_computing_system
1.4\(1m\)
ciscounified_computing_system
1.4\(3i\)
ciscounified_computing_system
1.4\(3l\)
ciscounified_computing_system
1.4\(3m\)
ciscounified_computing_system
1.4\(3q\)
ciscounified_computing_system
1.4\(3s\)
ciscounified_computing_system
1.4\(3u\)
ciscounified_computing_system
1.4\(3y\)
ciscounified_computing_system
1.4\(4f\)
ciscounified_computing_system
1.4\(4g\)
ciscounified_computing_system
1.4\(4i\)
ciscounified_computing_system
1.4\(4j\)
ciscounified_computing_system
1.4\(4k\)
ciscounified_computing_system
1.4_base:_base
ciscounified_computing_system
2.0\(1m\)
ciscounified_computing_system
2.0\(1q\)
ciscounified_computing_system
2.0\(1s\)
ciscounified_computing_system
2.0\(1t\)
ciscounified_computing_system
2.0\(1w\)
ciscounified_computing_system
2.0\(1x\)
ciscounified_computing_system
2.0\(2m\)
ciscounified_computing_system
2.0\(2q\)
ciscounified_computing_system
2.0\(2r\)
ciscounified_computing_system
2.0\(3a\)
ciscounified_computing_system
2.0\(3b\)
ciscounified_computing_system
2.0\(3c\)
ciscounified_computing_system
2.0\(4a\)
ciscounified_computing_system
2.0\(4b\)
ciscounified_computing_system
2.0\(4d\)
ciscounified_computing_system
2.0\(5a\)
ciscounified_computing_system
2.0\(5b\)
ciscounified_computing_system
2.0\(5c\)
ciscounified_computing_system
2.0_base:_base
ciscounified_computing_system
2.1\(1a\)
ciscounified_computing_system
2.1\(1b\)
ciscounified_computing_system
2.1\(1d\)
ciscounified_computing_system
2.1\(1e\)
ciscounified_computing_system
2.1\(1f\)
ciscounified_computing_system
2.1\(2a\)
ciscounified_computing_system
2.1_base:_base
ciscounified_computing_system
2.2\(1b\)
ciscounified_computing_system
2.2\(1c\)
ciscounified_computing_system
2.2\(1d\)
ciscounified_computing_system
2.2\(1e\)
ciscounified_computing_system
2.2\(1f\)
ciscounified_computing_system
2.2\(1g\)
ciscounified_computing_system
2.2\(1h\)
ciscounified_computing_system
2.2\(2c\)
ciscounified_computing_system
2.2\(2c\)a
ciscounified_computing_system
2.2\(3a\)
ciscounified_computing_system
2.2\(3b\)
ciscounified_computing_system
2.2\(3c\)
ciscounified_computing_system
2.2\(3d\)
ciscounified_computing_system
2.2\(3e\)
ciscounified_computing_system
2.2\(3f\)
ciscounified_computing_system
2.2\(3g\)
ciscounified_computing_system
2.2\(4b\)
ciscounified_computing_system
2.2\(4c\)
ciscounified_computing_system
2.2\(5a\)
ciscounified_computing_system
2.2_base:_base
ciscounified_computing_system
3.0\(1c\)
ciscounified_computing_system
3.0\(1d\)
ciscounified_computing_system
3.0\(1e\)
ciscounified_computing_system
3.0\(2c\)
ciscounified_computing_system
3.0\(2d\)
𝑥
= Vulnerable software versions