CVE-2016-1374: Cisco Unified Computing System Performance Manager

High severity, CVSS 8.8. EPSS: 2.7% chance of exploitation in the next 30 days.

The web framework in Cisco Unified Computing System (UCS) Performance Manager 2.0.0 and earlier allows remote authenticated users to execute arbitrary commands via crafted parameters in a GET request, aka Bug ID CSCuy07827.

Affected products

  • Cisco Unified Computing System Performance Manager: version 1.0_base only; version 1.1.0 only; version 1.1.1 only; version 2.0.0 only

Published 2016-07-28. Last modified 2026-06-17.