CVE-2015-4259: Cisco Unified Computing System

Medium severity, CVSS 4.3. EPSS: 0.8% chance of exploitation in the next 30 days.

The Integrated Management Controller on Cisco Unified Computing System (UCS) C servers with software 1.5(3) and 1.6(0.16) has a default SSL certificate, which makes it easier for man-in-the-middle attackers to bypass cryptographic protection mechanisms by leveraging knowledge of a private key, aka Bug IDs CSCum56133 and CSCum56177.

Affected products

  • Cisco Unified Computing System: version 1.5(3) only; version 1.6(0.16) only

Published 2015-07-10. Last modified 2026-06-17.