vendor:
UCS Manager
by:
thatchriseckert
7,5
CVSS
HIGH
Shellshock
78
CWE
Product Name: UCS Manager
Affected Version From: 2.1(1b)
Affected Version To: 2.1(1b)
Patch Exists: YES
Related CWE: CVE-2014-6278
CPE: a:cisco:ucs_manager:2.1
Metasploit:
https://www.rapid7.com/db/vulnerabilities/cisco-xe-cve-2014-6278/, https://www.rapid7.com/db/vulnerabilities/pulse-secure-pulse-connect-secure-cve-2014-6278/, https://www.rapid7.com/db/vulnerabilities/oracle-solaris-cve-2014-6278/, https://www.rapid7.com/db/vulnerabilities/gnu-bash-cve-2014-6278/, https://www.rapid7.com/db/vulnerabilities/suse-cve-2014-6278/, https://www.rapid7.com/db/vulnerabilities/gentoo-linux-cve-2014-6278/, https://www.rapid7.com/db/vulnerabilities/alpine-linux-cve-2014-6278/, https://www.rapid7.com/db/vulnerabilities/f5-big-ip-cve-2014-6278/
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: None
2014
Cisco UCS Manager 2.1(1b) Shellshock Exploit
This exploit generates a reverse shell to a nc listener. It is confirmed on version 2.1(1b), but more are likely vulnerable.
Mitigation:
Cisco has released an advisory for this vulnerability and recommends users to upgrade to the latest version of the software.