CVE-2021-34736
published 2021-10-21CVE-2021-34736: A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) Software could allow an unauthenticated, remote attacker…
high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) Software could allow an unauthenticated, remote attacker to cause the web-based management interface to unexpectedly restart. The vulnerability is due to insufficient input validation on the web-based management interface. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected device. A successful exploit could allow the attacker to cause the interface to restart, resulting in a denial of service (DoS) condition.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | cisco_unified_computing_system | — | — |
| cisco | integrated_management_controller | — | — |
| cisco | unified_computing_system | < 4.1\(2g\) | 4.1\(2g\) |
| cisco | unified_computing_system | < 4.1\(3e\) | 4.1\(3e\) |
| cisco | unified_computing_system | >= 4.2 < 4.2\(1b\) | 4.2\(1b\) |