CVE-2020-3504: Cisco UCS Manager Software Local Management CLI Denial of Service Vulnerability
A vulnerability in the local management (local-mgmt) CLI of Cisco UCS Manager Software could allow an authenticated, local attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to improper handling of CLI command parameters. An attacker could exploit this vulnerability by executing specific commands on the local-mgmt CLI on an affected device. A successful exploit could allow the attacker to cause internal system processes to fail to terminate properly, which could result in a buildup of stuck processes and lead to slowness in accessing the UCS Manager CLI and web UI. A sustained attack may result in a restart of internal UCS Manager processes and a temporary loss of access to the UCS Manager CLI and web UI.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-3504?
CVE-2020-3504 has a severity rating of medium, indicating potential impact from a denial of service condition.
How do I fix CVE-2020-3504?
To fix CVE-2020-3504, it is recommended to update your Cisco UCS Manager Software to the latest version provided by Cisco.
What causes the vulnerability CVE-2020-3504?
CVE-2020-3504 is caused by improper handling of command parameters in the local management CLI of Cisco UCS Manager Software.
Who is affected by CVE-2020-3504?
The CVE-2020-3504 vulnerability affects devices running Cisco UCS Manager Software.
What type of attack is possible with CVE-2020-3504?
CVE-2020-3504 can be exploited by an authenticated, local attacker to cause a denial of service (DoS) condition.