Known vulnerabilities in Cisco UCS Manager

Software CPE: cpe:2.3:a:cisco_systems:cisco_ucs_manager:*:*:*:*:*:*:*:*
Total vulnerabilities: 23
Public exploits: 0
Known exploited (KEV): 0
Highest CVSSv4 Score: 8.8

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting Cisco UCS Manager Cisco UCS Manager is affected by 23 known vulnerabilities: 5 medium, 17 low Critical High Medium Low

Vulnerabilities (23)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU123291 - Buffer Access with Incorrect Length Value
CVE-2026-20010
CWE-805
No
No
4.3(6e) 26.02.2026 SB2026022616
#VU123285 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2026-20099
CWE-78 Low
No
No
4.3(6c) 26.02.2026 SB2026022610
#VU123284 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2026-20091
CWE-79 Low
No
No
4.3(6a) 26.02.2026 SB2026022611
#VU123283 - Execution with Unnecessary Privileges
CVE-2026-20037
CWE-250 Low
No
No
4.3(6f) 26.02.2026 SB2026022612
#VU123281 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2026-20036
CWE-78 Low
No
No
4.3(6f), 6.0(2) 26.02.2026 SB2026022612
#VU114565 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2025-20342
CWE-79 Low
No
No
4.2(3p), 4.3(6a) 29.08.2025 SB2025082977
#VU114490 - URL Redirection to Untrusted Site ('Open Redirect')
CVE-2025-20317
CWE-601 Medium
No
No
4.2(3p), 4.3(6a) 28.08.2025 SB2025082828
#VU114485 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2025-20295
CWE-78 Low
No
No
4.2(3p), 4.3(6c) 28.08.2025 SB2025082817
#VU114484 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2025-20294
CWE-78 Low
No
No
4.2(3p), 4.3(6c) 28.08.2025 SB2025082817
#VU114483 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2025-20296
CWE-79 Low
No
No
4.2(3p), 4.3(6a) 28.08.2025 SB2025082816
#VU101221 - Improper Verification of Cryptographic Signature
CVE-2024-20397
CWE-347 Low
No
No
4.1(3n), 4.2(3n), 4.3(4a) 04.12.2024 SB2024120435
SB2025033110
#VU96599 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2024-20289
CWE-78 Low
No
No
4.2(3k), 4.3(4a) 28.08.2024 SB2024082886
#VU79993 - Improper input validation
CVE-2023-20200
CWE-20 Medium
No
No
4.1(3l)UCSM, 4.2(3d)UCSM 25.08.2023 SB2023082510
#VU72513 - Key Management Errors
CVE-2023-20016
CWE-320 Low
No
No
4.2(3c) 23.02.2023 SB2023022317
#VU72511 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2023-20015
CWE-78 Low
No
No
4.0(4o), 4.1(3k), 4.2(2d) 23.02.2023 SB2023022311
#VU72510 - Improper Authentication
CVE-2023-20012
CWE-287 Low
No
No
4.2(2d) 23.02.2023 SB2023022310
#VU60840 - Resource exhaustion
CVE-2022-20624
CWE-400 Medium
No
No
4.1(3h), 4.2(1l) 24.02.2022 SB2022022402
#VU56875 - Improper input validation
CVE-2021-34714
CWE-20 Medium
No
No
4.0(4l), 4.1(2c) 24.09.2021 SB2021092427
#VU52963 - URL Redirection to Untrusted Site ('Open Redirect')
CVE-2021-1397
CWE-601 Medium
No
No
- 07.05.2021 SB2021050705
#VU46100 - Improper input validation
CVE-2020-3504
CWE-20 Low
No
No
4.0.4i 27.08.2020 SB2020082714


Showing elements 1 - 20 out of 23