PT-2018-13015 · Cisco · Cisco Ucs Director+1
Published
2018-10-05
·
Updated
2019-10-09
·
CVE-2018-15404
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Cisco Integrated Management Controller (IMC) Supervisor and Cisco UCS Director (affected versions not specified)
Description
A denial of service (DoS) condition can be caused by an authenticated, remote attacker due to insufficient restrictions on resource size or amount via the web interface. The attacker can exploit this by sending a crafted HTTP request, potentially causing oversubscription of system resources or making a component unresponsive.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Allocation of Resources Without Limits
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Cisco Integrated Management Controller (Imc) Supervisor
Cisco Ucs Director