- Description
- A vulnerability in the web server of Cisco Integrated Management Controller (IMC) could allow an unauthenticated, remote attacker to cause the web server process to crash, causing a denial of service (DoS) condition on an affected system. The vulnerability is due to insufficient validation of user-supplied input on the web interface. An attacker could exploit this vulnerability by submitting a crafted HTTP request to certain endpoints of the affected software. A successful exploit could allow an attacker to cause the web server to crash. Physical access to the device may be required for a restart.
- Source
- ykramarz@cisco.com
- NVD status
- Analyzed
CVSS 3.1
- Type
- Primary
- Base score
- 7.5
- Impact score
- 3.6
- Exploitability score
- 3.9
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- Severity
- HIGH
CVSS 3.0
- Type
- Secondary
- Base score
- 7.5
- Impact score
- 3.6
- Exploitability score
- 3.9
- Vector string
- CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- Severity
- HIGH
CVSS 2.0
- Type
- Primary
- Base score
- 7.8
- Impact score
- 6.9
- Exploitability score
- 10
- Vector string
- AV:N/AC:L/Au:N/C:N/I:N/A:C
- Hype score
- Not currently trending
[
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:cisco:unified_computing_system:4.0\\(1c\\)hs3:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "39F8601E-730B-489B-AD2A-FD10FAF28595"
}
],
"operator": "OR"
}
]
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:cisco:integrated_management_controller_supervisor:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "F5549F4C-CF65-4F22-9675-EFAA99964CA0",
"versionEndExcluding": "4.0\\(2f\\)",
"versionStartIncluding": "4.0.0.0"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:cisco:ucs_c125_m5:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "ADD4A429-F168-460B-A964-8F1BD94C6387"
},
{
"criteria": "cpe:2.3:h:cisco:ucs_c4200:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "BD25964B-08B7-477E-A507-5FE5EE7CD286"
},
{
"criteria": "cpe:2.3:h:cisco:ucs_s3260:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "2FDC8A69-0914-44C1-8AEA-262E0A285C81"
}
],
"operator": "OR"
}
],
"operator": "AND"
}
]