CVE-2013-1186
UnknownEPSS 2.11%
Last modified
CVE-2013-1186 is a vulnerability of currently unknown severity. Cisco Unified Computing System (UCS) 1.x before 1.4(4) and 2.x before 2.0(2m) allows remote attackers to bypass KVM authentication via a crafted authentication request to a Cisco Integrated Management Controller (IMC), aka Bug ID CSCts53746.. EPSS estimates a 2.11% chance of exploitation in the next 30 days.
Description
Cisco Unified Computing System (UCS) 1.x before 1.4(4) and 2.x before 2.0(2m) allows remote attackers to bypass KVM authentication via a crafted authentication request to a Cisco Integrated Management Controller (IMC), aka Bug ID CSCts53746.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Cisco | Unified Computing System Infrastructure And Unified Computing System Software | 1.0 |
| Cisco | Unified Computing System Infrastructure And Unified Computing System Software | 1.0\(2k\) |
| Cisco | Unified Computing System Infrastructure And Unified Computing System Software | 1.1 |
| Cisco | Unified Computing System Infrastructure And Unified Computing System Software | 1.1\(1m\) |
| Cisco | Unified Computing System Infrastructure And Unified Computing System Software | 1.2 |
| Cisco | Unified Computing System Infrastructure And Unified Computing System Software | 1.2\(1\) |
| Cisco | Unified Computing System Infrastructure And Unified Computing System Software | 1.2\(1a\) |
| Cisco | Unified Computing System Infrastructure And Unified Computing System Software | 1.2\(1d\) |
| Cisco | Unified Computing System Infrastructure And Unified Computing System Software | 1.3\(1c\) |
| Cisco | Unified Computing System Infrastructure And Unified Computing System Software | 1.3\(1m\) |
| Cisco | Unified Computing System Infrastructure And Unified Computing System Software | 1.3\(1n\) |
| Cisco | Unified Computing System Infrastructure And Unified Computing System Software | 1.3\(1o\) |
| Cisco | Unified Computing System Infrastructure And Unified Computing System Software | 1.3\(1p\) |
| Cisco | Unified Computing System Infrastructure And Unified Computing System Software | 1.3\(1q\) |
| Cisco | Unified Computing System Infrastructure And Unified Computing System Software | 1.3\(1t\) |
| Cisco | Unified Computing System Infrastructure And Unified Computing System Software | 1.3\(1w\) |
| Cisco | Unified Computing System Infrastructure And Unified Computing System Software | 1.3\(1y\) |
| Cisco | Unified Computing System Infrastructure And Unified Computing System Software | 1.4\(1j\) |
| Cisco | Unified Computing System Infrastructure And Unified Computing System Software | 1.4\(1m\) |
| Cisco | Unified Computing System Infrastructure And Unified Computing System Software | 1.4\(3i\) |
| Cisco | Unified Computing System Infrastructure And Unified Computing System Software | 1.4\(3l\) |
| Cisco | Unified Computing System Infrastructure And Unified Computing System Software | 1.4\(3m\) |
| Cisco | Unified Computing System Infrastructure And Unified Computing System Software | 1.4\(3q\) |
| Cisco | Unified Computing System Infrastructure And Unified Computing System Software | 1.4\(3s\) |
| Cisco | Unified Computing System Infrastructure And Unified Computing System Software | 1.4\(3u\) |
| Cisco | Unified Computing System Infrastructure And Unified Computing System Software | 1.4\(3y\) |
| Cisco | Unified Computing System Infrastructure And Unified Computing System Software | 2.0\(1q\) |
| Cisco | Unified Computing System Infrastructure And Unified Computing System Software | 2.0\(1s\) |
| Cisco | Unified Computing System Infrastructure And Unified Computing System Software | 2.0\(1t\) |
| Cisco | Unified Computing System Infrastructure And Unified Computing System Software | 2.0\(1w\) |
| Cisco | Unified Computing System Infrastructure And Unified Computing System Software | 2.0\(1x\) |
| Cisco | Unified Computing System 6120xp Fabric Interconnect | All versions |
| Cisco | Unified Computing System 6140xp Fabric Interconnect | All versions |
| Cisco | Unified Computing System 6248up Fabric Interconnect | All versions |
| Cisco | Unified Computing System 6296up Fabric Interconnect | All versions |
| Cisco | Unified Computing System Integrated Management Controller | All versions |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2013-1186?
Cisco Unified Computing System (UCS) 1.x before 1.4(4) and 2.x before 2.0(2m) allows remote attackers to bypass KVM authentication via a crafted authentication request to a Cisco Integrated Management Controller (IMC), aka Bug ID CSCts53746.
How severe is CVE-2013-1186?
Severity scoring for CVE-2013-1186 is pending analysis. The EPSS model estimates a 2.11% probability of exploitation in the next 30 days.
How do I fix CVE-2013-1186?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2013
- CVE-2013-1180Buffer overflow in the SNMP implementation in Cisco NX-OS on…
- CVE-2013-1181Cisco NX-OS on Nexus 5500 devices 4.x and 5.x before 5.0(3)N…
- CVE-2013-1182The login page in the Web Console in the Manager component i…
- CVE-2013-1183Buffer overflow in the Intelligent Platform Management Inter…
- CVE-2013-1184The management API in the XML API management service in the …
- CVE-2013-1185The web interface in the Manager component in Cisco Unified …
- CVE-2013-1187The Connection Manager in Cisco Jabber Extensible Communicat…
- CVE-2013-1188Cisco Unified Communications Manager (CUCM) does not properl…
- CVE-2013-1189Cisco Universal Broadband (aka uBR) 10000 series routers, wh…
- CVE-2013-1190The C-Series Rack Server component 1.4 in Cisco Unified Comp…
- CVE-2013-1191Cisco NX-OS 6.1 before 6.1(5) on Nexus 7000 devices, when lo…
- CVE-2013-1192The JAR files on Cisco Device Manager for Cisco MDS 9000 dev…
Are you affected by CVE-2013-1186?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
