Edb-ID: 39568 CVE: 2014-6278 Author: THATCHRISSEC KERT Type: REMOTE Platform: HARDWARE Date: 2016-03-16 Vulnerable App: Cisco UCS Manager 2.1(1b) Exploit Verified: No Key Points: CVE Details: The vulnerability is associated with CVE-2014-6278, known as the Shellshock vulnerability. Vulnerable Version: Confirmed on Cisco UCS Manager 2.1(1b), but more versions may be vulnerable. Exploit Type: Remote command injection. Exploit Description: The exploit generates a reverse shell to a netcat listener, allowing an attacker to gain remote access. Usage: The exploit script requires the victim's IP, attacking host IP, and reverse shell port as parameters. Example Command: Listener Command: Advisory Link: