CVE-2021-1600
Published on: 07/22/2021 12:00:00 AM UTC
Last Modified on: 07/15/2022 05:52:00 PM UTC
CVE-2021-1600 - advisory for cisco-sa-ucsi2-iptaclbp-L8Dzs8m8
Source: Mitre Source: NIST CVE.ORG Print: PDF
Certain versions of Intersight Virtual Appliance from Cisco contain the following vulnerability:
Multiple vulnerabilities in Cisco Intersight Virtual Appliance could allow an unauthenticated, adjacent attacker to access sensitive internal services from an external interface. These vulnerabilities are due to insufficient restrictions for IPv4 or IPv6 packets that are received on the external management interface. An attacker could exploit these vulnerabilities by sending specific traffic to this interface on an affected device. A successful exploit could allow the attacker to access sensitive internal services and make configuration changes on the affected device.
- CVE-2021-1600 has been assigned by
[email protected] to track the vulnerability - currently rated as HIGH severity.
- The Cisco Product Security Incident Response Team (PSIRT) is not aware of any public announcements or malicious use of the vulnerabilities that are described in this advisory.
- Affected Vendor/Software:
Cisco - Cisco Intersight Virtual Appliance version n/a
CVSS3 Score: 8.3 - HIGH
Attack Vector ⓘ |
Attack Complexity |
Privileges Required |
User Interaction |
---|---|---|---|
ADJACENT_NETWORK | LOW | NONE | NONE |
Scope | Confidentiality Impact |
Integrity Impact |
Availability Impact |
UNCHANGED | LOW | HIGH | HIGH |
CVSS2 Score: 5.8 - MEDIUM
Access Vector ⓘ |
Access Complexity |
Authentication |
---|---|---|
ADJACENT_NETWORK | LOW | NONE |
Confidentiality Impact |
Integrity Impact |
Availability Impact |
PARTIAL | PARTIAL | PARTIAL |
CVE References
Description | Tags ⓘ | Link |
---|---|---|
Cisco Intersight Virtual Appliance IPv4 and IPv6 Forwarding Vulnerabilities | tools.cisco.com text/html |
![]() |
Known Affected Configurations (CPE V2.3)
Type | Vendor | Product | Version | Update | Edition | Language |
---|---|---|---|---|---|---|
Application | Cisco | Intersight Virtual Appliance | 1.0\(1\) | All | All | All |
- cpe:2.3:a:cisco:intersight_virtual_appliance:1.0\(1\):*:*:*:*:*:*:*:
Social Mentions
Source | Title | Posted (UTC) |
---|---|---|
![]() |
CVE-2021-1600 : Multiple vulnerabilities in Cisco Intersight Virtual Appliance could allow an unauthenticated, adja… twitter.com/i/web/status/1… | 2021-07-22 15:34:23 |
![]() |
CVE-2021-1600 Multiple vulnerabilities in Cisco Intersight Virtual Appliance could allow an unauthenticated, adjace… twitter.com/i/web/status/1… | 2021-07-23 07:09:46 |
![]() |
CVE-2021-1600 | 2021-07-22 15:38:21 |