CVE-2015-0599

Severity CVSS v4.0:
Pending analysis
Type:
CWE-254 Security Features
Publication date:
03/02/2015
Last modified:
12/04/2025

Description

The web interface in Cisco Integrated Management Controller in Cisco Unified Computing System (UCS) on C-Series Rack Servers does not properly restrict use of IFRAME elements, which makes it easier for remote attackers to conduct clickjacking attacks and unspecified other attacks via a crafted web site, related to a "cross-frame scripting (XFS)" issue, aka Bug ID CSCuf50138.

Vulnerable products and versions

CPE From Up to
cpe:2.3:h:cisco:unified_computing_system:-:*:*:*:*:*:*:*