CVE-2021-34736
Published on: 10/20/2021 12:00:00 AM UTC
Last Modified on: 10/26/2021 03:18:00 PM UTC
CVE-2021-34736 - advisory for cisco-sa-imc-gui-dos-TZjrFyZh
Source: Mitre Source: NIST CVE.ORG Print: PDF
Certain versions of Ucs C125 M5 from Cisco contain the following vulnerability:
A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) Software could allow an unauthenticated, remote attacker to cause the web-based management interface to unexpectedly restart. The vulnerability is due to insufficient input validation on the web-based management interface. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected device. A successful exploit could allow the attacker to cause the interface to restart, resulting in a denial of service (DoS) condition.
- CVE-2021-34736 has been assigned by
[email protected] to track the vulnerability - currently rated as HIGH severity.
- The Cisco PSIRT is not aware of any public announcements or malicious use of the vulnerability that is described in this advisory.
- Affected Vendor/Software:
Cisco - Cisco Unified Computing System (Managed) version n/a
CVSS3 Score: 7.5 - HIGH
Attack Vector ⓘ |
Attack Complexity |
Privileges Required |
User Interaction |
---|---|---|---|
NETWORK | LOW | NONE | NONE |
Scope | Confidentiality Impact |
Integrity Impact |
Availability Impact |
UNCHANGED | NONE | NONE | HIGH |
CVSS2 Score: 5 - MEDIUM
Access Vector ⓘ |
Access Complexity |
Authentication |
---|---|---|
NETWORK | LOW | NONE |
Confidentiality Impact |
Integrity Impact |
Availability Impact |
NONE | NONE | PARTIAL |
CVE References
Description | Tags ⓘ | Link |
---|---|---|
Cisco Integrated Management Controller GUI Denial of Service Vulnerability | tools.cisco.com text/html |
![]() |
Known Affected Configurations (CPE V2.3)
Type | Vendor | Product | Version | Update | Edition | Language |
---|---|---|---|---|---|---|
Hardware
| Cisco | Ucs C125 M5 | - | All | All | All |
Hardware
| Cisco | Ucs C220 M3 | - | All | All | All |
Hardware
| Cisco | Ucs C220 M4 | - | All | All | All |
Hardware
| Cisco | Ucs C220 M5 | - | All | All | All |
Hardware
| Cisco | Ucs C225 M6 | - | All | All | All |
Hardware
| Cisco | Ucs C22 M3 | - | All | All | All |
Hardware
| Cisco | Ucs C240 M3 | - | All | All | All |
Hardware
| Cisco | Ucs C240 M5 | - | All | All | All |
Hardware
| Cisco | Ucs C240 Sd M5 | - | All | All | All |
Hardware
| Cisco | Ucs C245 M6 | - | All | All | All |
Hardware
| Cisco | Ucs C24 M3 | - | All | All | All |
Hardware
| Cisco | Ucs C260 M2 | - | All | All | All |
Hardware
| Cisco | Ucs C3160 | - | All | All | All |
Hardware
| Cisco | Ucs C3260 | - | All | All | All |
Hardware
| Cisco | Ucs C4200 | - | All | All | All |
Hardware
| Cisco | Ucs C420 M3 | - | All | All | All |
Hardware
| Cisco | Ucs C460 M2 | - | All | All | All |
Hardware
| Cisco | Ucs C460 M4 | - | All | All | All |
Hardware
| Cisco | Ucs C480 M5 | - | All | All | All |
Hardware
| Cisco | Ucs C480 Ml M5 | - | All | All | All |
Hardware
| Cisco | Ucs C890 M5 | - | All | All | All |
Hardware
| Cisco | Ucs S3260 | - | All | All | All |
Application | Cisco | Unified Computing System | All | All | All | All |
- cpe:2.3:h:cisco:ucs_c125_m5:-:*:*:*:*:*:*:*:
- cpe:2.3:h:cisco:ucs_c220_m3:-:*:*:*:*:*:*:*:
- cpe:2.3:h:cisco:ucs_c220_m4:-:*:*:*:*:*:*:*:
- cpe:2.3:h:cisco:ucs_c220_m5:-:*:*:*:*:*:*:*:
- cpe:2.3:h:cisco:ucs_c225_m6:-:*:*:*:*:*:*:*:
- cpe:2.3:h:cisco:ucs_c22_m3:-:*:*:*:*:*:*:*:
- cpe:2.3:h:cisco:ucs_c240_m3:-:*:*:*:*:*:*:*:
- cpe:2.3:h:cisco:ucs_c240_m5:-:*:*:*:*:*:*:*:
- cpe:2.3:h:cisco:ucs_c240_sd_m5:-:*:*:*:*:*:*:*:
- cpe:2.3:h:cisco:ucs_c245_m6:-:*:*:*:*:*:*:*:
- cpe:2.3:h:cisco:ucs_c24_m3:-:*:*:*:*:*:*:*:
- cpe:2.3:h:cisco:ucs_c260_m2:-:*:*:*:*:*:*:*:
- cpe:2.3:h:cisco:ucs_c3160:-:*:*:*:*:*:*:*:
- cpe:2.3:h:cisco:ucs_c3260:-:*:*:*:*:*:*:*:
- cpe:2.3:h:cisco:ucs_c4200:-:*:*:*:*:*:*:*:
- cpe:2.3:h:cisco:ucs_c420_m3:-:*:*:*:*:*:*:*:
- cpe:2.3:h:cisco:ucs_c460_m2:-:*:*:*:*:*:*:*:
- cpe:2.3:h:cisco:ucs_c460_m4:-:*:*:*:*:*:*:*:
- cpe:2.3:h:cisco:ucs_c480_m5:-:*:*:*:*:*:*:*:
- cpe:2.3:h:cisco:ucs_c480_ml_m5:-:*:*:*:*:*:*:*:
- cpe:2.3:h:cisco:ucs_c890_m5:-:*:*:*:*:*:*:*:
- cpe:2.3:h:cisco:ucs_s3260:-:*:*:*:*:*:*:*:
- cpe:2.3:a:cisco:unified_computing_system:*:*:*:*:*:*:*:*:
Social Mentions
Source | Title | Posted (UTC) |
---|---|---|
![]() |
CVE-2021-34736 : A vulnerability in the web-based management interface of Cisco Integrated Management Controller… twitter.com/i/web/status/1… | 2021-10-21 02:59:55 |