Improper Certificate Validation in Cisco Unified Computing System - CVE-2021-1354
Published: February 4, 2021
Cisco Unified Computing System
Cisco Systems, Inc
Description
The vulnerability allows a remote attacker to compromise the target system.
The vulnerability exists due to improper certificate validation in the certificate registration process. A remote authenticated attacker can send a specially crafted HTTP request, register a rogue Cisco UCSM and gain access to Cisco UCS Central Software data and Cisco UCSM inventory data.