CVE-2017-12349: Cisco Unified Computing System Central Software
Medium severity, CVSS 5.4. EPSS: 0.9% chance of exploitation in the next 30 days.
Multiple vulnerabilities in the web-based management interface of Cisco UCS Central Software could allow a remote attacker to conduct a cross-site scripting (XSS) attack against a user of the affected interface or hijack a valid session ID from a user of the affected interface. Cisco Bug IDs: CSCvf71978, CSCvf71986.
Affected products
- Cisco Unified Computing System Central Software: version 2.2(1a)a only
Published 2017-11-30. Last modified 2026-06-17.