Not a U.S. government website. NDD is an independent vulnerability database by Volerion and is not affiliated with or endorsed by NIST or NVD.
VOLERION
Volerion Security Research

NOT DEFERRED DATABASE

VULNERABILITIES

CVE-2024-20344 Details

Description

A vulnerability in system resource management in Cisco UCS 6400 and 6500 Series Fabric Interconnects that are in Intersight Managed Mode (IMM) could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on the Device Console UI of an affected device. This vulnerability is due to insufficient rate-limiting of TCP connections to an affected device. An attacker could exploit this vulnerability by sending a high number of TCP packets to the Device Console UI. A successful exploit could allow an attacker to cause the Device Console UI process to crash, resulting in a DoS condition. A manual reload of the fabric interconnect is needed to restore complete functionality.

Metrics

CVSS 3.x Severity and Vector Strings:

References to Advisories, Solutions, and Tools

By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.

Weakness Enumeration

CWE-IDCWE NameSource
CWE-400Uncontrolled Resource Consumption[email protected]

Affected Products

ProductVersions
cisco imm management package
< 1.0.11-1582

CPE

  • cpe:2.3:a:cisco:imm_management_package:*:*:*:*:*:*:*:*

Remediation

  • No remediation found in references.
cisco ucs 64108
All versions

CPE

  • cpe:2.3:h:cisco:ucs_64108:-:*:*:*:*:*:*:*

Remediation

  • No remediation found in references.
cisco ucs 6454
All versions

CPE

  • cpe:2.3:h:cisco:ucs_6454:-:*:*:*:*:*:*:*

Remediation

  • No remediation found in references.
cisco ucs 6536
All versions

CPE

  • cpe:2.3:h:cisco:ucs_6536:-:*:*:*:*:*:*:*

Remediation

  • No remediation found in references.

Change History

6 change records found show changes


QUICK INFO

CVE Dictionary Entry:
CVE-2024-20344
NVD Published Date:
Feb 29, 2024
NVD Last Modified:
Jun 17, 2026
Source:
[email protected]