QID 316699

Date Published: 2021-05-25

QID 316699: Cisco UCS Manager Software Local Management CLI Denial of Service Vulnerability(cisco-sa-ucs-cli-dos-GQUxCnTe)

A vulnerability in the local management (local-mgmt) CLI of Cisco UCS Manager Software could allow an authenticated, local attacker to cause a denial of service (DoS) condition on an affected device.

Affected Products:
Cisco UCS 6400 Series Fabric Interconnects if they were running a vulnerable release of Cisco UCS Manager Software.

QID Detection Logic(Authenticated):
It checks for vulnerable version of Cisco UCS using show version Command.

A successful exploit could allow the attacker to cause internal system processes to fail to terminate properly, which could result in a buildup of stuck processes and lead to slowness in accessing the UCS Manager CLI and web UI.

  • CVSS V3 rated as Medium - 3.3 severity.
  • CVSS V2 rated as Low - 2.1 severity.
  • Solution

    Customers are advised to refer to cisco-sa-ucs-cli-dos-GQUxCnTe for more information.

    CVEs related to QID 316699

    Software Advisories
    Advisory ID Software Component Link
    cisco-sa-ucs-cli-dos-GQUxCnTe URL Logo tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ucs-cli-dos-GQUxCnTe