CVE-2013-1186 describes an authentication bypass vulnerability in Cisco Unified Computing System (UCS) versions 1.x before 1.4(4) and 2.x before 2.0(2m). This flaw allows remote attackers to bypass KVM authentication on a Cisco Integrated Management Controller (IMC) by sending a specially crafted authentication request. The vulnerability carries a CVSS score of 7.5 (High), indicating that it is remotely exploitable with low attack complexity and requires no authentication, potentially leading to partial confidentiality, integrity, and availability impacts. Its EPSS score is very low, suggesting a minimal probability of exploitation in the wild. There is no evidence of active exploitation, nor are there publicly available exploit modules in Metasploit, Nuclei, or ExploitDB. Community discussion and media coverage for this CVE are also non-existent, suggesting it has received very little attention since its disclosure.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.0CPE matchmatch criteria | cpe:2.3:o:cisco:unified_computing_system_infrastructure_and_unified_computing_system_software:1.0:*:*:*:*:*:*:* | ||
1.0\(2k\)CPE matchmatch criteria | cpe:2.3:o:cisco:unified_computing_system_infrastructure_and_unified_computing_system_software:1.0\(2k\):*:*:*:*:*:*:* | ||
1.1CPE matchmatch criteria | cpe:2.3:o:cisco:unified_computing_system_infrastructure_and_unified_computing_system_software:1.1:*:*:*:*:*:*:* | ||
1.1\(1m\)CPE matchmatch criteria | cpe:2.3:o:cisco:unified_computing_system_infrastructure_and_unified_computing_system_software:1.1\(1m\):*:*:*:*:*:*:* | ||
1.2CPE matchmatch criteria | cpe:2.3:o:cisco:unified_computing_system_infrastructure_and_unified_computing_system_software:1.2:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:P/I:P/A:P
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.