CVE Feed

    Dashboard / CVE / CVE-2024-20344

    CVE-2024-20344

    A vulnerability in system resource management in Cisco UCS 6400 and 6500 Series Fabric Interconnects that are in Intersight Managed Mode (IMM) could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on the Device Console UI of an affected device. This vulnerability is due to insufficient rate-limiting of TCP connections to an affected device. An attacker could exploit this vulnerability by sending a high number of TCP packets to the Device Console UI. A successful exploit could allow an attacker to cause the Device Console UI process to crash, resulting in a DoS condition. A manual reload of the fabric interconnect is needed to restore complete functionality.

    Published:Feb 28, 2024
    Last Modified:Aug 13, 2025
    EPS:Feb 28, 2024
    EPSS Score:0.00307
    CVSS Score:5.3

    Affected Products

    Vendor
    Cisco
    Product
    Imm Management Package
    Vendor
    Cisco
    Product
    Ucs 64108
    Vendor
    Cisco
    Product
    Ucs 6454
    Vendor
    Cisco
    Product
    Ucs 6536

    Exploits

    No exploit reference

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High