CVE-2021-1397
6.1
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Exploitability: 2.8 / Impact: 2.7
Source: NVD
Description
A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) Software could allow an unauthenticated, remote attacker to redirect a user to a malicious web page. This vulnerability is due to improper input validation of the parameters in an HTTP request. An attacker could exploit this vulnerability by persuading a user to click a crafted link. A successful exploit could allow the attacker to redirect a user to a malicious website. This vulnerability is known as an open redirect attack, which is used in phishing attacks to get users to visit malicious sites without their knowledge.
Affected (25)
Products: Cisco: Integrated Management Controller, Ucs Manager, Encs 5100 Firmware, Encs 5400 Firmware, C220 M6 Firmware, C225 M6 Firmware, C240 M6 Firmware, C245 M6 Firmware, C125 M5 Firmware, C220 M5 Firmware, C240 M5 Firmware, C480 M5 Firmware, C480 Ml M5 Firmware, Ucs E140s Firmware, Ucs E160s M3 Firmware, Ucs E180d M3 Firmware, Ucs E1120d M3 Firmware, Ucs E140s M2 Firmware, Ucs E180d M2 Firmware, Ucs E140s M1 Firmware, Ucs E140d Firmware, Ucs E140dp Firmware, Ucs E160d Firmware, Ucs E160dp M1 Firmware, Ucs S3260 Firmware
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before 3.2\(12.4\) | |
| Up to 4.1\(3b\) |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 4.4.2 |
| Running on/with | Platform Versions |
|---|---|
Cisco Encs 5100 | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 4.4.2 |
| Running on/with | Platform Versions |
|---|---|
Cisco Encs 5400 | All versions |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 4.1\(2f\) |
| Running on/with | Platform Versions |
|---|---|
Cisco C220 M6 | All versions |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 4.1\(2f\) |
| Running on/with | Platform Versions |
|---|---|
Cisco C225 M6 | All versions |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 4.1\(2f\) |
| Running on/with | Platform Versions |
|---|---|
Cisco C240 M6 | All versions |
Configuration G
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 4.1\(2f\) |
| Running on/with | Platform Versions |
|---|---|
Cisco C245 M6 | All versions |
Configuration H
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 4.1\(2f\) |
| Running on/with | Platform Versions |
|---|---|
Cisco C125 M5 | All versions |
Configuration I
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 4.1\(2f\) |
| Running on/with | Platform Versions |
|---|---|
Cisco C220 M5 | All versions |
Configuration J
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 4.1\(2f\) |
| Running on/with | Platform Versions |
|---|---|
Cisco C240 M5 | All versions |
Configuration K
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 4.1\(2f\) |
| Running on/with | Platform Versions |
|---|---|
Cisco C480 M5 | All versions |
Configuration L
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 4.1\(2f\) |
| Running on/with | Platform Versions |
|---|---|
Cisco C480 Ml M5 | All versions |
Configuration M
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 3.2\(11.5\) |
| Running on/with | Platform Versions |
|---|---|
Cisco Ucs E140s | All versions |
Configuration P
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 3.2\(11.5\) |
| Running on/with | Platform Versions |
|---|---|
Cisco Ucs E160s M3 | All versions |
Configuration Q
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 3.2\(11.5\) |
| Running on/with | Platform Versions |
|---|---|
Cisco Ucs E180d M3 | All versions |
Configuration R
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 3.2\(11.5\) |
| Running on/with | Platform Versions |
|---|---|
Cisco Ucs E1120d M3 | All versions |
Configuration S
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 3.2\(11.5\) |
| Running on/with | Platform Versions |
|---|---|
Cisco Ucs E140s M2 | All versions |
Configuration U
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 3.2\(11.5\) |
| Running on/with | Platform Versions |
|---|---|
Cisco Ucs E180d M2 | All versions |
Configuration V
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 3.2\(11.5\) |
| Running on/with | Platform Versions |
|---|---|
Cisco Ucs E140s M1 | All versions |
Configuration W
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 3.2\(11.5\) |
| Running on/with | Platform Versions |
|---|---|
Cisco Ucs E140d | All versions |
Configuration X
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 3.2\(11.5\) |
| Running on/with | Platform Versions |
|---|---|
Cisco Ucs E140dp | All versions |
Configuration Y
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 3.2\(11.5\) |
| Running on/with | Platform Versions |
|---|---|
Cisco Ucs E160d | All versions |
Configuration Z
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 3.2\(11.5\) |
| Running on/with | Platform Versions |
|---|---|
Cisco Ucs E160dp M1 | All versions |
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 4.0\(2o\) |
| Running on/with | Platform Versions |
|---|---|
Cisco Ucs S3260 | All versions |
References (2)
Source: psirt@cisco.com
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Timeline
No history available yet.