CVE-2021-1592
published 2021-08-25CVE-2021-1592: A vulnerability in the way Cisco UCS Manager software handles SSH sessions could allow an authenticated, remote attacker to cause a denial of service (DoS)…
PriorityP421medium4.3CVSS 3.1
AVNACLPRLUINSUCNINAL
EPSS
1.03%
60.2th percentile
A vulnerability in the way Cisco UCS Manager software handles SSH sessions could allow an authenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper resource management for established SSH sessions. An attacker could exploit this vulnerability by opening a significant number of SSH sessions on an affected device. A successful exploit could allow the attacker to cause a crash and restart of internal Cisco UCS Manager software processes and a temporary loss of access to the Cisco UCS Manager CLI and web UI. Note: The attacker must have valid user credentials to authenticate to the affected device.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | cisco_unified_computing_system | — | — |
| cisco | ucs_manager | — | — |
| cisco | unified_computing_system | >= 4.0 < 4.0\(4m\) | 4.0\(4m\) |
| cisco | unified_computing_system | >= 4.1 < 4.1\(3e\) | 4.1\(3e\) |
CVSS provenance
nvdv3.14.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:N/I:N/A:P
vendor_cisco4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco UCS Manager Software SSH Sessions Denial of Service Vulnerability
vendor_cisco·2021-08-25·CVSS 4.3
CVE-2021-1592 [MEDIUM] CWE-664 Cisco UCS Manager Software SSH Sessions Denial of Service Vulnerability
Cisco UCS Manager Software SSH Sessions Denial of Service Vulnerability
A vulnerability in the way Cisco UCS Manager software handles SSH sessions could allow an authenticated, remote attacker to cause a denial of service (DoS) condition on an affected device.
This vulnerability is due to improper resource management for established SSH sessions. An attacker could exploit this vulnerability by opening a significant number of SSH sessions on an affected device. A successful exploit could allow the attacker to cause a crash and restart of internal Cisco UCS Manager software processes and a temporary loss of access to the Cisco UCS Manager CLI and web UI.
Note: The attacker must have valid user credentials to authenticate to the affected device.
Cisco has released software updates that addr
Cisco
Cisco UCS Manager Software SSH Sessions Denial of Service Vulnerability
vendor_cisco·CVSS 3.1
CVE-2021-1592 Cisco UCS Manager Software SSH Sessions Denial of Service Vulnerability
CVE-2021-1592: Cisco UCS Manager Software SSH Sessions Denial of Service Vulnerability
A vulnerability in the way Cisco UCS Manager software handles SSH sessions could allow an authenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper resource management for established SSH sessions. An attacker could exploit this vulnerability by opening a significant number of SSH sessions on an affected device. A successful exploit could allow the attacker to cause a crash and restart of internal Cisco UCS Manager software processes and a temporary loss of access to the Cisco UCS Manager CLI and web UI. Note: The attacker must have valid user credentials to authenticate to the affected device. Cisco has released software upda
GHSA
GHSA-g536-3jmm-mp33: A vulnerability in the way Cisco UCS Manager software handles SSH sessions could allow an authenticated, remote attacker to cause a denial of service
ghsa_unreviewed·2022-05-24
CVE-2021-1592 [MEDIUM] CWE-770 GHSA-g536-3jmm-mp33: A vulnerability in the way Cisco UCS Manager software handles SSH sessions could allow an authenticated, remote attacker to cause a denial of service
A vulnerability in the way Cisco UCS Manager software handles SSH sessions could allow an authenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper resource management for established SSH sessions. An attacker could exploit this vulnerability by opening a significant number of SSH sessions on an affected device. A successful exploit could allow the attacker to cause a crash and restart of internal Cisco UCS Manager software processes and a temporary loss of access to the Cisco UCS Manager CLI and web UI. Note: The attacker must have valid user credentials to authenticate to the affected device.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2021-08-25
Published