CVE-2021-1397: Cisco Integrated Management Controller Open Redirect Vulnerability
A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) Software could allow an unauthenticated, remote attacker to redirect a user to a malicious web page. This vulnerability is due to improper input validation of the parameters in an HTTP request. An attacker could exploit this vulnerability by persuading a user to click a crafted link. A successful exploit could allow the attacker to redirect a user to a malicious website. This vulnerability is known as an open redirect attack, which is used in phishing attacks to get users to visit malicious sites without their knowledge.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID of this Cisco vulnerability?
The vulnerability ID is CVE-2021-1397.
What is the severity level of CVE-2021-1397?
The severity level of CVE-2021-1397 is medium.
Which software is affected by CVE-2021-1397?
The affected software includes Cisco Integrated Management Controller (IMC) Software, Cisco UCS Manager, and Cisco Encs 5100 Firmware.
How does the vulnerability in CVE-2021-1397 occur?
The vulnerability occurs due to improper input validation of the parameters in an HTTP request in the web-based management interface of Cisco Integrated Management Controller (IMC) Software.
Is there a fix available for CVE-2021-1397?
Yes, Cisco has released software updates to address the vulnerability. Please refer to the reference link for more information.