logo

Critical Security Flaw in Cisco UCS Manager Allows Malicious Command Injection

ID: 07e881ab-e41c-53be-a5f2-6df40f66c107

STIX ID: report--07e881ab-e41c-53be-a5f2-6df40f66c107

Feed Name: Cyber Press

Threat Score
55/100

Date Published: 2025-08-28

Date Updated: 2026-04-19

Author: Priya

...
...

**Cisco UCS Manager vulnerabilities (CVE-2025-20294, CVE-2025-20295):** Cisco disclosed two medium-severity input-validation flaws in UCS Manager affecting multiple Fabric Interconnect models that can allow command injection or file manipulation with administrative access; fixes are provided (4.2(3p), 4.3(6c), and UCS 6.0 is not vulnerable) and no workarounds exist, with no observed public exploitation to date.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.