Ucs Director

Vendor:

First CVE: Feb 22, 2014 · Active for 12 years

26
Total CVEs
More Total CVEs than 96% of tracked products
4.3
Avg CVEs / Year
Higher CVE frequency than 88% of tracked products
7.8
Avg CVSS
Higher Avg CVSS than 70% of tracked products
3.8%
KEV Rate
Higher KEV Rate than 98% of tracked products

Trends Over Time

The number and severity of CVEs published that impact Ucs Director over time

Volume of CVEsAvg CVSS Base Score
First CVE
Feb 22, 2014
12 years ago
Most Recent CVE
May 27, 2022
1,523 days ago

CVE Severity & Scoring

Ucs Director26 CVEs
All CVEs353,240 CVEs
MediumHighCritical
Attack Vector
Local1 (3.8%)
Network24 (92.3%)
Unknown1 (3.8%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low25 (96.2%)
High0 (0.0%)
Unknown1 (3.8%)
User Interaction
None20 (76.9%)
Unknown1 (3.8%)
Required5 (19.2%)
Privileges Required
Low6 (23.1%)
High5 (19.2%)
None14 (53.8%)
Unknown1 (3.8%)

Top CVEs

Signals from CVEs in this product scope (26 CVEs).

26 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect agai
Dec 10, 202110.099YESYES
A vulnerability in Cisco Integrated Management Controller (IMC) Supervisor, Cisco UCS Director, and Cisco UCS Director Express for Big Data could allow an unauthenticated, remote a
Aug 21, 20199.888NOYES
A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) Supervisor, Cisco UCS Director, and Cisco UCS Director Express for Big Data co
Aug 21, 20199.886NOYES
Multiple vulnerabilities in the REST API of Cisco UCS Director and Cisco UCS Director Express for Big Data may allow a remote attacker to bypass authentication or conduct directory
Apr 15, 20209.885NOYES
Multiple vulnerabilities in the REST API of Cisco UCS Director and Cisco UCS Director Express for Big Data may allow a remote attacker to bypass authentication or conduct directory
Apr 15, 20209.874NOYES
Multiple vulnerabilities in the REST API of Cisco UCS Director and Cisco UCS Director Express for Big Data may allow a remote attacker to bypass authentication or conduct directory
Apr 15, 20209.868NONO
Multiple vulnerabilities in the REST API of Cisco UCS Director and Cisco UCS Director Express for Big Data may allow a remote attacker to bypass authentication or conduct directory
Apr 15, 20209.865NONO
Multiple vulnerabilities in the REST API of Cisco UCS Director and Cisco UCS Director Express for Big Data may allow a remote attacker to bypass authentication or conduct directory
Apr 15, 20208.861NONO
A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) Supervisor, Cisco UCS Director, and Cisco UCS Director Express for Big Data co
Aug 21, 20197.257NOYES
Multiple vulnerabilities in the REST API of Cisco UCS Director and Cisco UCS Director Express for Big Data may allow a remote attacker to bypass authentication or conduct directory
Apr 15, 20208.854NONO

Exploit Exposure

Signals from CVEs in this product scope (26 CVEs).

CISA KEV
1 CVE
3.8% of CVEs· 98th percentile
Metasploit
6 CVEs
23.1% of CVEs· 98th percentile
Nuclei
1 CVE
3.8% of CVEs· 97th percentile
ExploitDB
3 CVEs
11.5% of CVEs· 86th percentile

Social Chatter

Signals from CVEs in this product scope (26 CVEs).

Media Mentions

Signals from CVEs in this product scope (26 CVEs).

Top CNAs Publishing CVEs For Ucs Director

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
6.7.3.098.755.5%02
6.7\(2.0\)19.84.5%00
6.7.2.098.755.5%02
6.7\(1.1\)19.84.5%00
6.7.1.0128.752.3%04
6.7\(0.0.67265\)38.966.2%03
6.7.0.0128.752.3%04
6.6.2.098.755.5%02
6.6\(1.0\)16.51.8%00
6.6.1.0128.652.0%04
6.6.0.0128.652.0%04
6.616.11.2%00
6.5.0.498.755.5%02
6.5.0.398.755.5%02
6.5.0.298.755.5%02
6.5.0.198.755.5%02
6.5\(0.0.65832\)18.80.9%00
6.5.0.0118.756.6%04
6.0.1.398.755.5%02
6.0.1.298.755.5%02