CVE-2021-34736

Severity CVSS v4.0:
Pending analysis
Type:
CWE-20 Input Validation
Publication date:
21/10/2021
Last modified:
07/11/2023

Description

A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) Software could allow an unauthenticated, remote attacker to cause the web-based management interface to unexpectedly restart. The vulnerability is due to insufficient input validation on the web-based management interface. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected device. A successful exploit could allow the attacker to cause the interface to restart, resulting in a denial of service (DoS) condition.

Vulnerable products and versions

CPE From Up to
cpe:2.3:h:cisco:ucs_c125_m5:-:*:*:*:*:*:*:*
cpe:2.3:h:cisco:ucs_c22_m3:-:*:*:*:*:*:*:*
cpe:2.3:h:cisco:ucs_c220_m3:-:*:*:*:*:*:*:*
cpe:2.3:h:cisco:ucs_c220_m4:-:*:*:*:*:*:*:*
cpe:2.3:h:cisco:ucs_c220_m5:-:*:*:*:*:*:*:*
cpe:2.3:h:cisco:ucs_c225_m6:-:*:*:*:*:*:*:*
cpe:2.3:h:cisco:ucs_c24_m3:-:*:*:*:*:*:*:*
cpe:2.3:h:cisco:ucs_c240_m3:-:*:*:*:*:*:*:*
cpe:2.3:h:cisco:ucs_c240_m5:-:*:*:*:*:*:*:*
cpe:2.3:h:cisco:ucs_c240_sd_m5:-:*:*:*:*:*:*:*
cpe:2.3:h:cisco:ucs_c245_m6:-:*:*:*:*:*:*:*
cpe:2.3:h:cisco:ucs_c260_m2:-:*:*:*:*:*:*:*
cpe:2.3:h:cisco:ucs_c3160:-:*:*:*:*:*:*:*
cpe:2.3:h:cisco:ucs_c3260:-:*:*:*:*:*:*:*
cpe:2.3:h:cisco:ucs_c420_m3:-:*:*:*:*:*:*:*