5.3
CVE-2021-1234
- EPSS 0.17%
- Veröffentlicht 18.11.2024 16:15:08
- Zuletzt bearbeitet 04.08.2025 14:44:52
- Quelle psirt@cisco.com
- Teams Watchlist Login
- Unerledigt Login
A vulnerability in the cluster management interface of Cisco SD-WAN vManage Software could allow an unauthenticated, remote attacker to view sensitive information on an affected system. To be affected by this vulnerability, the vManage software must be in cluster mode. This vulnerability is due to the absence of authentication for sensitive information in the cluster management interface. An attacker could exploit this vulnerability by sending a crafted request to the cluster management interface of an affected system. A successful exploit could allow the attacker to view sensitive information on the affected system.Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.
Verknüpft mit AI von unstrukturierten Daten zu bestehenden CPE der NVD
Diese Information steht angemeldeten Benutzern zur Verfügung. Login
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Cisco ≫ Catalyst Sd-wan Manager Version17.2.4
Cisco ≫ Catalyst Sd-wan Manager Version17.2.5
Cisco ≫ Catalyst Sd-wan Manager Version17.2.6
Cisco ≫ Catalyst Sd-wan Manager Version17.2.7
Cisco ≫ Catalyst Sd-wan Manager Version17.2.8
Cisco ≫ Catalyst Sd-wan Manager Version17.2.9
Cisco ≫ Catalyst Sd-wan Manager Version17.2.10
Cisco ≫ Catalyst Sd-wan Manager Version18.2.0
Cisco ≫ Catalyst Sd-wan Manager Version18.3.0
Cisco ≫ Catalyst Sd-wan Manager Version18.3.1
Cisco ≫ Catalyst Sd-wan Manager Version18.3.1.1
Cisco ≫ Catalyst Sd-wan Manager Version18.3.3
Cisco ≫ Catalyst Sd-wan Manager Version18.3.3.1
Cisco ≫ Catalyst Sd-wan Manager Version18.3.4
Cisco ≫ Catalyst Sd-wan Manager Version18.3.5
Cisco ≫ Catalyst Sd-wan Manager Version18.3.6
Cisco ≫ Catalyst Sd-wan Manager Version18.3.6.1
Cisco ≫ Catalyst Sd-wan Manager Version18.3.7
Cisco ≫ Catalyst Sd-wan Manager Version18.3.8
Cisco ≫ Catalyst Sd-wan Manager Version18.4.0
Cisco ≫ Catalyst Sd-wan Manager Version18.4.0.1
Cisco ≫ Catalyst Sd-wan Manager Version18.4.1
Cisco ≫ Catalyst Sd-wan Manager Version18.4.3
Cisco ≫ Catalyst Sd-wan Manager Version18.4.4
Cisco ≫ Catalyst Sd-wan Manager Version18.4.5
Cisco ≫ Catalyst Sd-wan Manager Version18.4.6
Cisco ≫ Catalyst Sd-wan Manager Version18.4.302
Cisco ≫ Catalyst Sd-wan Manager Version18.4.303
Cisco ≫ Catalyst Sd-wan Manager Version18.4.501_es
Cisco ≫ Catalyst Sd-wan Manager Version19.0.0
Cisco ≫ Catalyst Sd-wan Manager Version19.0.1a
Cisco ≫ Catalyst Sd-wan Manager Version19.1.0
Cisco ≫ Catalyst Sd-wan Manager Version19.2.0
Cisco ≫ Catalyst Sd-wan Manager Version19.2.1
Cisco ≫ Catalyst Sd-wan Manager Version19.2.2
Cisco ≫ Catalyst Sd-wan Manager Version19.2.3
Cisco ≫ Catalyst Sd-wan Manager Version19.2.31
Cisco ≫ Catalyst Sd-wan Manager Version19.2.32
Cisco ≫ Catalyst Sd-wan Manager Version19.2.097
Cisco ≫ Catalyst Sd-wan Manager Version19.2.098
Cisco ≫ Catalyst Sd-wan Manager Version19.2.099
Cisco ≫ Catalyst Sd-wan Manager Version19.2.929
Cisco ≫ Catalyst Sd-wan Manager Version19.3.0
Cisco ≫ Catalyst Sd-wan Manager Version20.1.1
Cisco ≫ Catalyst Sd-wan Manager Version20.1.1.1
Cisco ≫ Catalyst Sd-wan Manager Version20.1.2
Cisco ≫ Catalyst Sd-wan Manager Version20.1.2_937
Cisco ≫ Catalyst Sd-wan Manager Version20.1.12
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Typ | Quelle | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.17% | 0.392 |
Quelle | Base Score | Exploit Score | Impact Score | Vector String |
---|---|---|---|---|
psirt@cisco.com | 5.3 | 3.9 | 1.4 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
|
CWE-497 Exposure of Sensitive System Information to an Unauthorized Control Sphere
The product does not properly prevent sensitive system-level information from being accessed by unauthorized actors who do not have the same level of access to the underlying system as the product does.