- Description
- A vulnerability in system resource management in Cisco UCS 6400 and 6500 Series Fabric Interconnects that are in Intersight Managed Mode (IMM) could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on the Device Console UI of an affected device. This vulnerability is due to insufficient rate-limiting of TCP connections to an affected device. An attacker could exploit this vulnerability by sending a high number of TCP packets to the Device Console UI. A successful exploit could allow an attacker to cause the Device Console UI process to crash, resulting in a DoS condition. A manual reload of the fabric interconnect is needed to restore complete functionality.
- Source
- psirt@cisco.com
- NVD status
- Analyzed
- Products
- imm_management_package
CVSS 3.1
- Type
- Secondary
- Base score
- 5.3
- Impact score
- 1.4
- Exploitability score
- 3.9
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
- Severity
- MEDIUM
- psirt@cisco.com
- CWE-400
- Hype score
- Not currently trending
[
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:cisco:imm_management_package:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "DA6E23FC-BD7B-4407-92B2-6D0890022B95",
"versionEndExcluding": "1.0.11-1582"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:cisco:ucs_64108:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "BC04D48B-8B2F-45E1-A445-A87E92E790B8"
},
{
"criteria": "cpe:2.3:h:cisco:ucs_6454:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "4FD096B7-6F8E-4E48-9EC4-9A10AA7D9AA0"
},
{
"criteria": "cpe:2.3:h:cisco:ucs_6536:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "0C36A364-DBC0-44DA-9DB0-6CC8E9D074BF"
}
],
"operator": "OR"
}
],
"operator": "AND"
}
]