Critical Security Flaw in Cisco UCS Manager Allows Malicious Command Injection
ID: 07e881ab-e41c-53be-a5f2-6df40f66c107
STIX ID: report--07e881ab-e41c-53be-a5f2-6df40f66c107
Feed Name: Cyber Press
Threat Score
**Cisco UCS Manager vulnerabilities (CVE-2025-20294, CVE-2025-20295):** Cisco disclosed two medium-severity input-validation flaws in UCS Manager affecting multiple Fabric Interconnect models that can allow command injection or file manipulation with administrative access; fixes are provided (4.2(3p), 4.3(6c), and UCS 6.0 is not vulnerable) and no workarounds exist, with no observed public exploitation to date.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
