#VU24157 Missing Authentication for Critical Function in Cisco UCS Director - CVE-2019-16003
Published: January 9, 2020
Cisco UCS Director
Cisco Systems, Inc
Description
The vulnerability allows a remote attacker to download system log files from the target device.
The vulnerability exists due to an issue in the authentication logic of the web-based management interface. A remote attacker can send a specially crafted request and download log files if they were previously generated by an administrator.