Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2021-1592

Опубликовано: 25 авг. 2021
Источник: nvd
CVSS3: 4.3
CVSS2: 4
EPSS Низкий

Описание

A vulnerability in the way Cisco UCS Manager software handles SSH sessions could allow an authenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper resource management for established SSH sessions. An attacker could exploit this vulnerability by opening a significant number of SSH sessions on an affected device. A successful exploit could allow the attacker to cause a crash and restart of internal Cisco UCS Manager software processes and a temporary loss of access to the Cisco UCS Manager CLI and web UI. Note: The attacker must have valid user credentials to authenticate to the affected device.

Уязвимые конфигурации

Конфигурация 1

Одновременно

Одно из

cpe:2.3:a:cisco:unified_computing_system:*:*:*:*:*:*:*:*
Версия от 4.0 (включая) до 4.0\(4m\) (исключая)
cpe:2.3:a:cisco:unified_computing_system:*:*:*:*:*:*:*:*
Версия от 4.1 (включая) до 4.1\(3e\) (исключая)

Одно из

cpe:2.3:h:cisco:unified_computing_system_64108:-:*:*:*:*:*:*:*
cpe:2.3:h:cisco:unified_computing_system_6454:-:*:*:*:*:*:*:*

EPSS

Процентиль: 61%
0.00415
Низкий

4.3 Medium

CVSS3

4 Medium

CVSS2

Дефекты

CWE-664
CWE-770

Связанные уязвимости

github
больше 3 лет назад

A vulnerability in the way Cisco UCS Manager software handles SSH sessions could allow an authenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper resource management for established SSH sessions. An attacker could exploit this vulnerability by opening a significant number of SSH sessions on an affected device. A successful exploit could allow the attacker to cause a crash and restart of internal Cisco UCS Manager software processes and a temporary loss of access to the Cisco UCS Manager CLI and web UI. Note: The attacker must have valid user credentials to authenticate to the affected device.

CVSS3: 4.3
fstec
больше 4 лет назад

Уязвимость микропрограммного обеспечения маршрутизаторов Cisco UCS 6400, связанная с недостаточным контролем ресурса в период его существования, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 61%
0.00415
Низкий

4.3 Medium

CVSS3

4 Medium

CVSS2

Дефекты

CWE-664
CWE-770