Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-pvcf-6vj4-mpr5

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 3.3

Описание

A vulnerability in the local management (local-mgmt) CLI of Cisco UCS Manager Software could allow an authenticated, local attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to improper handling of CLI command parameters. An attacker could exploit this vulnerability by executing specific commands on the local-mgmt CLI on an affected device. A successful exploit could allow the attacker to cause internal system processes to fail to terminate properly, which could result in a buildup of stuck processes and lead to slowness in accessing the UCS Manager CLI and web UI. A sustained attack may result in a restart of internal UCS Manager processes and a temporary loss of access to the UCS Manager CLI and web UI.

A vulnerability in the local management (local-mgmt) CLI of Cisco UCS Manager Software could allow an authenticated, local attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to improper handling of CLI command parameters. An attacker could exploit this vulnerability by executing specific commands on the local-mgmt CLI on an affected device. A successful exploit could allow the attacker to cause internal system processes to fail to terminate properly, which could result in a buildup of stuck processes and lead to slowness in accessing the UCS Manager CLI and web UI. A sustained attack may result in a restart of internal UCS Manager processes and a temporary loss of access to the UCS Manager CLI and web UI.

EPSS

Процентиль: 38%
0.00168
Низкий

3.3 Low

CVSS3

Дефекты

CWE-400
CWE-664

Связанные уязвимости

CVSS3: 3.3
nvd
больше 5 лет назад

A vulnerability in the local management (local-mgmt) CLI of Cisco UCS Manager Software could allow an authenticated, local attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to improper handling of CLI command parameters. An attacker could exploit this vulnerability by executing specific commands on the local-mgmt CLI on an affected device. A successful exploit could allow the attacker to cause internal system processes to fail to terminate properly, which could result in a buildup of stuck processes and lead to slowness in accessing the UCS Manager CLI and web UI. A sustained attack may result in a restart of internal UCS Manager processes and a temporary loss of access to the UCS Manager CLI and web UI.

CVSS3: 3.3
fstec
больше 5 лет назад

Уязвимость компонента local-mgmt микропрограммного обеспечения маршрутизаторов Cisco UCS 6400 Series Fabric Interconnects, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 38%
0.00168
Низкий

3.3 Low

CVSS3

Дефекты

CWE-400
CWE-664