Improper Certificate Validation in Cisco Unified Computing System (UCS) - CVE-2021-1354
Published: February 4, 2021
Vulnerability details
The vulnerability allows a remote attacker to compromise the target system.
The vulnerability exists due to improper certificate validation in the certificate registration process. A remote authenticated attacker can send a specially crafted HTTP request, register a rogue Cisco UCSM and gain access to Cisco UCS Central Software data and Cisco UCSM inventory data.