PT-2021-3952 · Cisco · Cisco Intersight Virtual Appliance

Published

2021-07-21

·

Updated

2022-07-15

·

CVE-2021-1600

CVSS v3.1

8.3

High

VectorAV:A/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H
Name of the Vulnerable Software and Affected Versions Cisco Intersight Virtual Appliance (affected versions not specified)
Description The issue is related to insufficient restrictions for IPv4 or IPv6 packets received on the external management interface, allowing an unauthenticated, adjacent attacker to access sensitive internal services from an external interface. An attacker could exploit this by sending specific traffic to the interface on an affected device, potentially allowing access to sensitive internal services and making configuration changes on the affected device.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Access Control

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2021-04470
CVE-2021-1600

Affected Products

Cisco Intersight Virtual Appliance