QID 730135

Date Published: 2021-07-15

QID 730135: Cisco Prime Infrastructure Denial of Service (DoS) Vulnerability in Open Secure Sockets Layer (OpenSSL) Affecting Cisco Products (cisco-sa-openssl-2021-GHY28dJd)

Cisco Prime Infrastructure is affected by CVE-2021-3449, that could allow a remote unauthenticated attacker to crash
a TLS server resulting in a Denial of Service (DoS) condition.

Affected Products
Cisco Prime Infrastructure Versions below: From Version 3.7 Prior to 3.9(1)

QID Detection Logic (Unauthenticated):
The QID checks for the Vulnerable Cisco Prime Infrastructure version retrieved via a GET request to a "webacs/js/xmp/nls/xmp.js"

Successful exploitation could allow a remote unauthenticated attacker to crash a TLS server resulting in a Denial of Service (DoS) condition.

  • CVSS V3 rated as High - 7.4 severity.
  • CVSS V2 rated as Medium - 5.8 severity.
  • Solution

    Customers are advised to refer to cisco-sa-openssl-2021-GHY28dJd for more information.

    CVEs related to QID 730135

    Software Advisories
    Advisory ID Software Component Link
    cisco-sa-openssl-2021-GHY28dJd URL Logo tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-openssl-2021-GHY28dJd