Cisco Security Advisory
Follow
Cisco UCS Manager Software Command Injection Vulnerabilities
Multiple vulnerabilities exist in Cisco UCS Manager Software's command-line interface and web-based management interface. These vulnerabilities can be exploited by an authenticated attacker with administrative privileges. The attacker could successfully perform command injection attacks on an affected system. Successful exploitation allows for privilege escalation to the root user. Cisco has released software updates that resolve these vulnerabilities. Unfortunately, there are no workarounds available to mitigate these issues. This advisory provides details on these specific vulnerabilities. It is part of a larger bundle of advisories released in August 2025. The security impact rating for these vulnerabilities is considered Medium. The affected CVEs are CVE-2025-20294 and CVE-2025-20295.