Description
A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) Software could allow an unauthenticated, remote attacker to cause the web-based management interface to unexpectedly restart. The vulnerability is due to insufficient input validation on the web-based management interface. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected device. A successful exploit could allow the attacker to cause the interface to restart, resulting in a denial of service (DoS) condition.
Published: 2021-10-21
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2021-21386 A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) Software could allow an unauthenticated, remote attacker to cause the web-based management interface to unexpectedly restart. The vulnerability is due to insufficient input validation on the web-based management interface. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected device. A successful exploit could allow the attacker to cause the interface to restart, resulting in a denial of service (DoS) condition.
History

Thu, 07 Nov 2024 22:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Subscriptions

Cisco Ucs C125 M5 Ucs C220 M3 Ucs C220 M4 Ucs C220 M5 Ucs C225 M6 Ucs C22 M3 Ucs C240 M3 Ucs C240 M5 Ucs C240 Sd M5 Ucs C245 M6 Ucs C24 M3 Ucs C260 M2 Ucs C3160 Ucs C3260 Ucs C4200 Ucs C420 M3 Ucs C460 M2 Ucs C460 M4 Ucs C480 M5 Ucs C480 Ml M5 Ucs C890 M5 Ucs S3260 Unified Computing System
cve-icon MITRE

Status: PUBLISHED

Assigner: cisco

Published:

Updated: 2024-11-07T21:46:33.524Z

Reserved: 2021-06-15T00:00:00.000Z

Link: CVE-2021-34736

cve-icon Vulnrichment

Updated: 2024-08-04T00:19:48.111Z

cve-icon NVD

Status : Modified

Published: 2021-10-21T03:15:06.890

Modified: 2024-11-21T06:11:04.973

Link: CVE-2021-34736

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses