CVE-2014-7989
Description
Local users can gain shell privileges on Cisco UCS B-Series blade servers by crafting ping6 or traceroute6 commands.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Local users can gain shell privileges on Cisco UCS B-Series blade servers by crafting ping6 or traceroute6 commands.
Vulnerability
A command injection vulnerability exists in the Cisco Unified Computing System (UCS) on B-Series blade servers. The flaw allows local users to execute arbitrary shell commands by supplying specially crafted arguments to the ping6 or traceroute6 commands. The vulnerability is tracked as Bug ID CSCuq38176 and affects all versions of the UCS software prior to the fix [1].
Exploitation
An attacker must have local access to the UCS system (e.g., via SSH or console). No additional authentication is required beyond the initial login. The attacker crafts a ping6 or traceroute6 command with malicious input that escapes the intended command restrictions, leading to execution of arbitrary shell commands with the privileges of the user running the command [1].
Impact
Successful exploitation allows the attacker to gain shell privileges on the affected UCS B-Series blade server. This can lead to full compromise of the system, including unauthorized access to sensitive data, modification of system configurations, and potential lateral movement within the network [1].
Mitigation
Cisco has published a security notice (Cisco Security Notice CVE-2014-7989) that provides details on the vulnerability and recommends workarounds. As of the publication date, no software update has been released; users are advised to restrict local access to trusted personnel and monitor for suspicious command usage. The advisory may be updated with a fixed version in the future [1].
AI Insight generated on May 23, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
9- cpe:2.3:h:cisco:b200_m3:-:*:*:*:*:*:*:*
- cpe:2.3:h:cisco:b200_m4:-:*:*:*:*:*:*:*
- cpe:2.3:h:cisco:b22_m3:-:*:*:*:*:*:*:*
- cpe:2.3:h:cisco:b230_m2:-:*:*:*:*:*:*:*
- cpe:2.3:h:cisco:b260_m4:-:*:*:*:*:*:*:*
- cpe:2.3:h:cisco:b420_m3:-:*:*:*:*:*:*:*
- cpe:2.3:h:cisco:b440_m2:-:*:*:*:*:*:*:*
- cpe:2.3:h:cisco:b460_m4:-:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
4News mentions
0No linked articles in our index yet.