Cisco UCS Manager Software Com... Note

Cisco UCS Manager Software Command Injection Vulnerabilities

Multiple vulnerabilities exist in Cisco UCS Manager Software's command-line interface and web-based management interface. These vulnerabilities can be exploited by an authenticated attacker with administrative privileges. The attacker could successfully perform command injection attacks on an affected system. Successful exploitation allows for privilege escalation to the root user. Cisco has released software updates that resolve these vulnerabilities. Unfortunately, there are no workarounds available to mitigate these issues. This advisory provides details on these specific vulnerabilities. It is part of a larger bundle of advisories released in August 2025. The security impact rating for these vulnerabilities is considered Medium. The affected CVEs are CVE-2025-20294 and CVE-2025-20295.