CVE-2017-6604: Cisco Unified Computing System

Medium severity, CVSS 6.1. EPSS: 1.2% chance of exploitation in the next 30 days.

A vulnerability in the web interface of Cisco Integrated Management Controller (IMC) Software could allow an unauthenticated, remote attacker to redirect a user to a malicious web page. This vulnerability affects the following Cisco products running Cisco IMC Software: Unified Computing System (UCS) B-Series M3 and M4 Blade Servers, Unified Computing System (UCS) C-Series M3 and M4 Rack Servers. More Information: CSCvc37931. Known Affected Releases: 3.1(2c)B.

Affected products

  • Cisco Unified Computing System: version 2.2(8b) only; version 3.0(1c) only; version 3.1(2c)b only

Published 2017-04-07. Last modified 2026-06-17.