---
title: Cisco UCS Central Software - Critical Vulnerability Advisory
description: If you are currently running Cisco UCS Central Software you should update the software immediately.
image: https://email.networksgroup.com/hubfs/Blogs/info-2150941_1280.png
---

- info@networksgroup.com
- [Contact Us](https://www.networksgroup.com/contact/)

- <https://www.facebook.com/networksgroupinc/>
- <https://www.facebook.com/networksgroupinc/>
- <https://twitter.com/networksgroup>
- [mailto:info@networksgroup.com](mailto:info@networksgroup.com)

[![NetWorks Group](https://email.networksgroup.com/hubfs/Networksgroup%20August%202017/Images/NWG_Black_Logo_300-154x42.png "NetWorks Group") ![NetWorks Group](https://email.networksgroup.com/hubfs/Networksgroup%20August%202017/Images/NWG_Black_Logo_750px.png "NetWorks Group") ![NetWorks Group](https://email.networksgroup.com/hubfs/Networksgroup%20August%202017/Images/NWG_Black_Logo_1500px.png "NetWorks Group")](https://www.networksgroup.com/)

- [Home](https://www.networksgroup.com/)
- Detect & Respond 
    - [Managed Detection & Response](https://www.networksgroup.com/managed-detection-response/)
    - [Endpoint Managed Detection & Response](https://www.networksgroup.com/managed-detection-response/endpoint-mdr/)
- Ethical Hacking 
    - [Full Scope Penetration Test](https://www.networksgroup.com/full-scope-penetration-test/)
    - [Web Application Security Test](https://www.networksgroup.com/web-application-security-test/)
- Security Services 
    - [Managed Security Infrastructure](https://www.networksgroup.com/managed-security-services/)
    - [Compliance Services](https://www.networksgroup.com/pci/)
    - [Vulnerability Management](https://www.networksgroup.com/vulnerability-management/)
    - [Security Architecture Review](https://www.networksgroup.com/security-architecture-review/)
- Resources 
    - [Blog](http://blog.networksgroup.com/)
    - [Library](https://www.networksgroup.com/library/)
- Company 
    - [About](https://www.networksgroup.com/about/)
    - [Contact Us](https://www.networksgroup.com/contact/)
    - [Careers](https://www.networksgroup.com/careers/)
    - [Partners](https://www.networksgroup.com/partners/)

<https://email.networksgroup.com/cisco-ucs-central-software-critical-vulnerability-advisory#sidr>

[![NetWorks Group](https://email.networksgroup.com/hubfs/Networksgroup%20August%202017/Images/NWG_Black_Logo_750px.png "NetWorks Group")](https://www.networksgroup.com/)

- [Home](https://www.networksgroup.com/)
- Detect & Respond 
    - [Managed Detection & Response](https://www.networksgroup.com/managed-detection-response/)
    - [Endpoint Managed Detection & Response](https://www.networksgroup.com/managed-detection-response/endpoint-mdr/)
- Ethical Hacking 
    - [Full Scope Penetration Test](https://www.networksgroup.com/full-scope-penetration-test/)
    - [Web Application Security Test](https://www.networksgroup.com/web-application-security-test/)
- Security Services 
    - [Managed Security Infrastructure](https://www.networksgroup.com/managed-security-services/)
    - [Compliance Services](https://www.networksgroup.com/pci/)
    - [Vulnerability Management](https://www.networksgroup.com/vulnerability-management/)
    - [Security Architecture Review](https://www.networksgroup.com/security-architecture-review/)
- Resources 
    - [Blog](http://blog.networksgroup.com/)
    - [Library](https://www.networksgroup.com/library/)
- Company 
    - [About](https://www.networksgroup.com/about/)
    - [Contact Us](https://www.networksgroup.com/contact/)
    - [Careers](https://www.networksgroup.com/careers/)
    - [Partners](https://www.networksgroup.com/partners/)

# NetWorks Group Blog

# Cisco UCS Central Software - Critical Vulnerability Advisory

Posted by [NetWorks Group](https://email.networksgroup.com/author/networks-group) on May 8, 2015 9:08:00 AM

![](https://email.networksgroup.com/hubfs/Portraits/NWG.png)

Find me on:

[Facebook](https://www.facebook.com/networksgroupinc/) [LinkedIn](https://www.linkedin.com/company/networks-group) [Twitter](https://twitter.com/networksgroup)

- [Tweet](https://twitter.com/share)

### Affected Product Cisco UCS Central Software versions 1.2 and earlier

**If you are currently running Cisco UCS Central Software you should update the software immediately.**

Cisco has announced a critical vulnerability in its UCS Central Software product.  The UCS Central Software is a web application framework that can be used to manage a Cisco UCS domain.  If successfully exploited, an unauthenticated remote user could execute arbitrary commands with the privileges of the root user on the vulnerable system.

This vulnerability has been given an initial CVSS score of 10, which represents the highest severity ranking.  CVSS, the *Common Vulnerability Scoring System,* is an industry standard mechanism used to assess the severity of computer security vulnerabilities. More information about the CVSS system can be found at [https://www.first.org/cvss/faq](https://www.first.org/cvss/faq).

At the time of this writing, there is no known publicly available exploit code.

### Next Steps

- Customers running version 1.2 or earlier of the UCS Central Software should upgrade to version 1.3(1a) which was released by Cisco on May 6, 2015.  The direct download link is [https://software.cisco.com/download/release.html?mdfid=284308174&release=1.3%281a%29&relind=AVAILABLE&i=rm&softwareid=284308194&rellifecycle=&reltype=latest](https://software.cisco.com/download/release.html?mdfid=284308174&release=1.3%281a%29&relind=AVAILABLE&i=rm&softwareid=284308194&rellifecycle=&reltype=latest)
- NWG will monitor Managed Services customers’ networks and will enable IPS signatures for this vulnerability when they become available.
- As details regarding this vulnerability emerge, NWG will also offer Vulnerability Management customers proactive scanning to determine if they are affected by this issue.

### Links

- Cisco Security Advisory  
  [http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20150506-ucsc](http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20150506-ucsc)
- CVE Details  
  [https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2015-0701](https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2015-0701)
- UCS Central Software patched version 1.3(1a)  
  [https://software.cisco.com/download/release.html?mdfid=284308174&release=1.3%281a%29&relind=AVAILABLE&i=rm&softwareid=284308194&rellifecycle=&reltype=latest](https://software.cisco.com/download/release.html?mdfid=284308174&release=1.3%281a%29&relind=AVAILABLE&i=rm&softwareid=284308194&rellifecycle=&reltype=latest)
- NetWorks Group updates regarding this vulnerability  
  [https://www.networksgroup.com/blog](https://www.networksgroup.com/blog)

If you have questions regarding this notice please call us at 734-827-1400, option 3 or email [support@networksgroup.com](mailto:support@networksgroup.com).   

 Topics: [Device Management](https://email.networksgroup.com/topic/device-management), [Information Security](https://email.networksgroup.com/topic/information-security), [Threat Advisory](https://email.networksgroup.com/topic/threat-advisory)

### Subscribe to our blog!

### Stay Informed!

### Recent Posts

### Posts by Topic

- [Information Security (50)](https://email.networksgroup.com/topic/information-security)
- [Threat Management (34)](https://email.networksgroup.com/topic/threat-management)
- [Ethical Hacking (31)](https://email.networksgroup.com/topic/ethical-hacking)
- [Managed Detection & Response (25)](https://email.networksgroup.com/topic/managed-detection-response)
- [Penetration Testing (21)](https://email.networksgroup.com/topic/penetration-testing)
- [Vulnerability Management (12)](https://email.networksgroup.com/topic/vulnerability-management)
- [Compliance (11)](https://email.networksgroup.com/topic/compliance)
- [Security Monitoring (11)](https://email.networksgroup.com/topic/security-monitoring)
- [Healthcare (9)](https://email.networksgroup.com/topic/healthcare)
- [Threat Advisory (8)](https://email.networksgroup.com/topic/threat-advisory)
- [Threat Hunting (7)](https://email.networksgroup.com/topic/threat-hunting)
- [Security Architecture Review (6)](https://email.networksgroup.com/topic/security-architecture-review)
- [HIPAA (5)](https://email.networksgroup.com/topic/hipaa)
- [Device Management (4)](https://email.networksgroup.com/topic/device-management)
- [Incident Response (4)](https://email.networksgroup.com/topic/incident-response)
- [Events (1)](https://email.networksgroup.com/topic/events)
- [PCI (1)](https://email.networksgroup.com/topic/pci)

see all

###### About Us

NetWorks Group is a Managed Detection & Response (MDR) and Ethical Hacking Service provider. We help organizations detect and respond to advanced cyber security threats through a powerful combination of our proprietary threat detection platform, expertise and security tools. Our unique approach to security not only helps you stay ahead of cyber criminals but also helps you reduce cost and increase efficiency.

###### More Links

- [Home](https://www.networksgroup.com/)
- [Blog](http://blog.networksgroup.com/)
- [About](https://www.networksgroup.com/about/)

###### Contact Us

(888) 798-1012  
 info@networksgroup.com  
 www.networksgroup.com

- <https://www.facebook.com/networksgroupinc/>
- <https://www.linkedin.com/company/networks-group>
- <https://twitter.com/networksgroup>

© 2017 - NetWorks Group