CVE-2021-34736
published 2021-10-21CVE-2021-34736: A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) Software could allow an unauthenticated, remote attacker…
PriorityP344high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
1.23%
65.5th percentile
A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) Software could allow an unauthenticated, remote attacker to cause the web-based management interface to unexpectedly restart. The vulnerability is due to insufficient input validation on the web-based management interface. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected device. A successful exploit could allow the attacker to cause the interface to restart, resulting in a denial of service (DoS) condition.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | cisco_unified_computing_system | — | — |
| cisco | integrated_management_controller | — | — |
| cisco | unified_computing_system | < 4.1\(2g\) | 4.1\(2g\) |
| cisco | unified_computing_system | < 4.1\(3e\) | 4.1\(3e\) |
| cisco | unified_computing_system | >= 4.2 < 4.2\(1b\) | 4.2\(1b\) |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
vendor_cisco5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco Integrated Management Controller GUI Denial of Service Vulnerability
vendor_cisco·2021-10-20·CVSS 5.3
CVE-2021-34736 [MEDIUM] CWE-20 Cisco Integrated Management Controller GUI Denial of Service Vulnerability
Cisco Integrated Management Controller GUI Denial of Service Vulnerability
A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) Software could allow an unauthenticated, remote attacker to cause the web-based management interface to unexpectedly restart.
The vulnerability is due to insufficient input validation on the web-based management interface. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected device. A successful exploit could allow the attacker to cause the interface to restart, resulting in a denial of service (DoS) condition.
Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.
This advisory is available at the foll
Cisco
Cisco Integrated Management Controller GUI Denial of Service Vulnerability
vendor_cisco·CVSS 3.1
CVE-2021-34736 Cisco Integrated Management Controller GUI Denial of Service Vulnerability
CVE-2021-34736: Cisco Integrated Management Controller GUI Denial of Service Vulnerability
A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) Software could allow an unauthenticated, remote attacker to cause the web-based management interface to unexpectedly restart. The vulnerability is due to insufficient input validation on the web-based management interface. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected device. A successful exploit could allow the attacker to cause the interface to restart, resulting in a denial of service (DoS) condition. Cisco has released software updates that address this vulnerability. There are no
CVSS: 3.1
CWE: CWE-20, CWE-20
Bug IDs: CSCvy91321
GHSA
GHSA-q459-pjhx-263x: A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) Software could allow an unauthenticated, remote
ghsa_unreviewed·2022-05-24
CVE-2021-34736 [HIGH] CWE-20 GHSA-q459-pjhx-263x: A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) Software could allow an unauthenticated, remote
A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) Software could allow an unauthenticated, remote attacker to cause the web-based management interface to unexpectedly restart. The vulnerability is due to insufficient input validation on the web-based management interface. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected device. A successful exploit could allow the attacker to cause the interface to restart, resulting in a denial of service (DoS) condition.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2021-10-21
Published