CVE-2021-1592 MEDIUM

CVE-2021-1592: Cisco UCS Manager Software SSH Sessions Denial of Service Vulnerability

Vendor Cisco
Product Cisco Unified Computing System (Managed)
Weakness CWE-664
Published August 25, 2021
Last update November 7, 2024

CVSS base score

4.3/10
Attack vector Network
Attack complexity Low
Privileges required Low
User interaction None
Confidentiality None
Integrity None

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L

What the vulnerability does

01Description

A vulnerability in the way Cisco UCS Manager software handles SSH sessions could allow an authenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper resource management for established SSH sessions. An attacker could exploit this vulnerability by opening a significant number of SSH sessions on an affected device. A successful exploit could allow the attacker to cause a crash and restart of internal Cisco UCS Manager software processes and a temporary loss of access to the Cisco UCS Manager CLI and web UI. Note: The attacker must have valid user credentials to authenticate to the affected device.

Key dates

02Disclosure timeline

August 25, 2021 CVE published
November 7, 2024 Record updated