MEDIUM · 4.7

CVE-2021-1397

A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) Software could allow an unauthenticated, remote attacker to redirect a user to a malicious web pag...

Vulnerability Description

A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) Software could allow an unauthenticated, remote attacker to redirect a user to a malicious web page. This vulnerability is due to improper input validation of the parameters in an HTTP request. An attacker could exploit this vulnerability by persuading a user to click a crafted link. A successful exploit could allow the attacker to redirect a user to a malicious website. This vulnerability is known as an open redirect attack, which is used in phishing attacks to get users to visit malicious sites without their knowledge.

CVSS Score

4.7

MEDIUM

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
CHANGED
Confidentiality
NONE
Integrity
LOW
Availability
NONE

Affected Products

VendorProductVersions
CiscoIntegrated Management Controller< 3.2\(12.4\)
CiscoUcs Manager<= 4.1\(3b\)
CiscoEncs 5100 Firmware<= 4.4.2
CiscoEncs 5100-
CiscoEncs 5400 Firmware<= 4.4.2
CiscoEncs 5400-
CiscoC220 M6 Firmware<= 4.1\(2f\)
CiscoC220 M6-
CiscoC225 M6 Firmware<= 4.1\(2f\)
CiscoC225 M6-
CiscoC240 M6 Firmware<= 4.1\(2f\)
CiscoC240 M6-
CiscoC245 M6 Firmware<= 4.1\(2f\)
CiscoC245 M6-
CiscoC125 M5 Firmware<= 4.1\(2f\)
CiscoC125 M5-
CiscoC220 M5 Firmware<= 4.1\(2f\)
CiscoC220 M5-
CiscoC240 M5 Firmware<= 4.1\(2f\)
CiscoC240 M5-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2021-1397?

CVE-2021-1397 is a vulnerability with a CVSS score of 4.7 (MEDIUM). A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) Software could allow an unauthenticated, remote attacker to redirect a user to a malicious web pag...

How severe is CVE-2021-1397?

CVE-2021-1397 has been rated MEDIUM with a CVSS base score of 4.7/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2021-1397?

Check the references section above for vendor advisories and patch information. Affected products include: Cisco Integrated Management Controller, Cisco Ucs Manager, Cisco Encs 5100 Firmware, Cisco Encs 5100, Cisco Encs 5400 Firmware.