QID 730135
Date Published: 2021-07-15
QID 730135: Cisco Prime Infrastructure Denial of Service (DoS) Vulnerability in Open Secure Sockets Layer (OpenSSL) Affecting Cisco Products (cisco-sa-openssl-2021-GHY28dJd)
Cisco Prime Infrastructure is affected by CVE-2021-3449, that could allow a remote unauthenticated attacker to crash
a TLS server resulting in a Denial of Service (DoS) condition.
Affected Products
Cisco Prime Infrastructure Versions below:
From Version 3.7 Prior to 3.9(1)
QID Detection Logic (Unauthenticated):
The QID checks for the Vulnerable Cisco Prime Infrastructure version retrieved via a GET request to a "webacs/js/xmp/nls/xmp.js"
Successful exploitation could allow a remote unauthenticated attacker to crash a TLS server resulting in a Denial of Service (DoS) condition.
Solution
Customers are advised to refer to cisco-sa-openssl-2021-GHY28dJd for more information.
Vendor References
- cisco-sa-openssl-2021-GHY28dJd -
tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-openssl-2021-GHY28dJd
CVEs related to QID 730135
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| cisco-sa-openssl-2021-GHY28dJd |
|