CVE-2013-1182
Last modified
CVE-2013-1182 is a vulnerability of currently unknown severity. The login page in the Web Console in the Manager component in Cisco Unified Computing System (UCS) before 1.0(2h), 1.1 before 1.1(1j), and 1.3(x) allows remote attackers to bypass LDAP authentication via a malformed request, aka Bug ID CSCtc91207.. EPSS estimates a 3.51% chance of exploitation in the next 30 days.
Description
The login page in the Web Console in the Manager component in Cisco Unified Computing System (UCS) before 1.0(2h), 1.1 before 1.1(1j), and 1.3(x) allows remote attackers to bypass LDAP authentication via a malformed request, aka Bug ID CSCtc91207.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Cisco | Unified Computing System Infrastructure And Unified Computing System Software | <= 1.0 |
| Cisco | Unified Computing System Infrastructure And Unified Computing System Software | 1.1 |
| Cisco | Unified Computing System Infrastructure And Unified Computing System Software | 1.3\(1c\) |
| Cisco | Unified Computing System Infrastructure And Unified Computing System Software | 1.3\(1m\) |
| Cisco | Unified Computing System Infrastructure And Unified Computing System Software | 1.3\(1n\) |
| Cisco | Unified Computing System Infrastructure And Unified Computing System Software | 1.3\(1o\) |
| Cisco | Unified Computing System Infrastructure And Unified Computing System Software | 1.3\(1p\) |
| Cisco | Unified Computing System Infrastructure And Unified Computing System Software | 1.3\(1q\) |
| Cisco | Unified Computing System Infrastructure And Unified Computing System Software | 1.3\(1t\) |
| Cisco | Unified Computing System Infrastructure And Unified Computing System Software | 1.3\(1w\) |
| Cisco | Unified Computing System Infrastructure And Unified Computing System Software | 1.3\(1y\) |
| Cisco | Unified Computing System 6120xp Fabric Interconnect | All versions |
| Cisco | Unified Computing System 6140xp Fabric Interconnect | All versions |
| Cisco | Unified Computing System 6248up Fabric Interconnect | All versions |
| Cisco | Unified Computing System 6296up Fabric Interconnect | All versions |
| Cisco | Unified Computing System Integrated Management Controller | All versions |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2013-1182?
How severe is CVE-2013-1182?
How do I fix CVE-2013-1182?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2013
- CVE-2013-1176The DSP card on Cisco TelePresence MCU 4500 and 4501 devices…
- CVE-2013-1177SQL injection vulnerability in Cisco Network Admission Contr…
- CVE-2013-1178Multiple buffer overflows in the Cisco Discovery Protocol (C…
- CVE-2013-1179Multiple buffer overflows in the (1) SNMP and (2) License Ma…
- CVE-2013-1180Buffer overflow in the SNMP implementation in Cisco NX-OS on…
- CVE-2013-1181Cisco NX-OS on Nexus 5500 devices 4.x and 5.x before 5.0(3)N…
- CVE-2013-1183Buffer overflow in the Intelligent Platform Management Inter…
- CVE-2013-1184The management API in the XML API management service in the …
- CVE-2013-1185The web interface in the Manager component in Cisco Unified …
- CVE-2013-1186Cisco Unified Computing System (UCS) 1.x before 1.4(4) and 2…
- CVE-2013-1187The Connection Manager in Cisco Jabber Extensible Communicat…
- CVE-2013-1188Cisco Unified Communications Manager (CUCM) does not properl…
Are you affected by CVE-2013-1182?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
