QID 317025

Date Published: 2021-09-01

QID 317025: Cisco UCS Manager Software SSH Sessions Denial of Service Vulnerability (cisco-sa-ucs-ssh-dos-MgvmyrQy)

A vulnerability in the way Cisco UCS Manager software handles SSH sessions could allow an authenticated, remote attacker to cause a denial of service (DoS) condition on an affected device.

Affected Products:
Cisco UCS 6400 Series Fabric Interconnects devices if they were running a vulnerable release of Cisco UCS Manager software.

QID Detection Logic(Authenticated):
It checks for vulnerable version of Cisco UCS using show version Command.

A successful exploit could allow the attacker to cause a crash and restart of internal Cisco UCS Manager software processes and a temporary loss of access to the Cisco UCS Manager CLI and web UI.

  • CVSS V3 rated as Medium - 4.3 severity.
  • CVSS V2 rated as Medium - 4 severity.
  • Solution

    Customers are advised to refer to cisco-sa-ucs-ssh-dos-MgvmyrQy for more information.

    CVEs related to QID 317025

    Software Advisories
    Advisory ID Software Component Link
    cisco-sa-ucs-ssh-dos-MgvmyrQy URL Logo tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ucs-ssh-dos-MgvmyrQy