cisco-sa-imc-gui-dos-TZjrFyZh: Cisco Integrated Management Controller GUI Denial of Service Vulnerability
A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) Software could allow an unauthenticated, remote attacker to cause the web-based management interface to unexpectedly restart. The vulnerability is due to insufficient input validation on the web-based management interface. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected device. A successful exploit could allow the attacker to cause the interface to restart, resulting in a denial of service (DoS) condition. Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability. This advisory is available at the following link:https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-imc-gui-dos-TZjrFyZh
Affected Software
Event History
Frequently Asked Questions
What is the severity of cisco-sa-imc-gui-dos-TZjrFyZh?
The severity of cisco-sa-imc-gui-dos-TZjrFyZh is critical due to its potential to allow unauthenticated remote attackers to disrupt the management interface.
How do I fix cisco-sa-imc-gui-dos-TZjrFyZh?
To fix cisco-sa-imc-gui-dos-TZjrFyZh, upgrade to the patched versions of Cisco UCS C-Series and S-Series software as specified in the advisory.
Which products are affected by cisco-sa-imc-gui-dos-TZjrFyZh?
The affected products include Cisco UCS C-Series Rack Servers and Cisco UCS S-Series Storage Servers running specific versions of the software.
What are the consequences of the cisco-sa-imc-gui-dos-TZjrFyZh vulnerability?
The consequences of the cisco-sa-imc-gui-dos-TZjrFyZh vulnerability include the potential for the web management interface to restart unexpectedly, impacting server management.
Is the cisco-sa-imc-gui-dos-TZjrFyZh vulnerability exploitable without authentication?
Yes, the cisco-sa-imc-gui-dos-TZjrFyZh vulnerability can be exploited by unauthenticated remote attackers.