7.5

CVE-2021-34736

A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) Software could allow an unauthenticated, remote attacker to cause the web-based management interface to unexpectedly restart. The vulnerability is due to insufficient input validation on the web-based management interface. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected device. A successful exploit could allow the attacker to cause the interface to restart, resulting in a denial of service (DoS) condition.

Data is provided by the National Vulnerability Database (NVD)
CiscoUnified Computing System Version < 4.1\(2g\)
   CiscoUcs C125 M5 Version-
   CiscoUcs C22 M3 Version-
   CiscoUcs C220 M3 Version-
   CiscoUcs C220 M4 Version-
   CiscoUcs C220 M5 Version-
   CiscoUcs C225 M6 Version-
   CiscoUcs C24 M3 Version-
   CiscoUcs C240 M3 Version-
   CiscoUcs C240 M5 Version-
   CiscoUcs C240 Sd M5 Version-
   CiscoUcs C245 M6 Version-
   CiscoUcs C260 M2 Version-
   CiscoUcs C3160 Version-
   CiscoUcs C3260 Version-
   CiscoUcs C420 M3 Version-
   CiscoUcs C4200 Version-
   CiscoUcs C460 M2 Version-
   CiscoUcs C460 M4 Version-
   CiscoUcs C480 M5 Version-
   CiscoUcs C480 Ml M5 Version-
   CiscoUcs C890 M5 Version-
CiscoUnified Computing System Version >= 4.2 < 4.2\(1b\)
   CiscoUcs C125 M5 Version-
   CiscoUcs C22 M3 Version-
   CiscoUcs C220 M3 Version-
   CiscoUcs C220 M4 Version-
   CiscoUcs C220 M5 Version-
   CiscoUcs C225 M6 Version-
   CiscoUcs C24 M3 Version-
   CiscoUcs C240 M3 Version-
   CiscoUcs C240 M5 Version-
   CiscoUcs C240 Sd M5 Version-
   CiscoUcs C245 M6 Version-
   CiscoUcs C260 M2 Version-
   CiscoUcs C3160 Version-
   CiscoUcs C3260 Version-
   CiscoUcs C420 M3 Version-
   CiscoUcs C4200 Version-
   CiscoUcs C460 M2 Version-
   CiscoUcs C460 M4 Version-
   CiscoUcs C480 M5 Version-
   CiscoUcs C480 Ml M5 Version-
   CiscoUcs C890 M5 Version-
CiscoUnified Computing System Version < 4.1\(3e\)
   CiscoUcs S3260 Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.16% 0.331
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:N/I:N/A:P
psirt@cisco.com 5.3 3.9 1.4
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.