6.5

CVE-2021-1484

A vulnerability in the web UI of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to inject arbitrary commands on an affected system and cause a denial of service (DoS) condition.
This vulnerability is due to improper input validation of user-supplied input to the device template configuration. An attacker could exploit this vulnerability by submitting crafted input to the device template configuration. A successful exploit could allow the attacker to cause a DoS condition on the affected system.Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.

Verknüpft mit AI von unstrukturierten Daten zu bestehenden CPE der NVD
This information is available to logged-in users.
Data is provided by the National Vulnerability Database (NVD)
CiscoCatalyst Sd-wan Manager Version17.2.4
CiscoCatalyst Sd-wan Manager Version17.2.5
CiscoCatalyst Sd-wan Manager Version17.2.6
CiscoCatalyst Sd-wan Manager Version17.2.7
CiscoCatalyst Sd-wan Manager Version17.2.8
CiscoCatalyst Sd-wan Manager Version17.2.9
CiscoCatalyst Sd-wan Manager Version17.2.10
CiscoCatalyst Sd-wan Manager Version18.2.0
CiscoCatalyst Sd-wan Manager Version18.3.0
CiscoCatalyst Sd-wan Manager Version18.3.1
CiscoCatalyst Sd-wan Manager Version18.3.1.1
CiscoCatalyst Sd-wan Manager Version18.3.3
CiscoCatalyst Sd-wan Manager Version18.3.3.1
CiscoCatalyst Sd-wan Manager Version18.3.4
CiscoCatalyst Sd-wan Manager Version18.3.5
CiscoCatalyst Sd-wan Manager Version18.3.6
CiscoCatalyst Sd-wan Manager Version18.3.6.1
CiscoCatalyst Sd-wan Manager Version18.3.7
CiscoCatalyst Sd-wan Manager Version18.3.8
CiscoCatalyst Sd-wan Manager Version18.4.0
CiscoCatalyst Sd-wan Manager Version18.4.0.1
CiscoCatalyst Sd-wan Manager Version18.4.1
CiscoCatalyst Sd-wan Manager Version18.4.3
CiscoCatalyst Sd-wan Manager Version18.4.4
CiscoCatalyst Sd-wan Manager Version18.4.5
CiscoCatalyst Sd-wan Manager Version18.4.302
CiscoCatalyst Sd-wan Manager Version18.4.303
CiscoCatalyst Sd-wan Manager Version18.4.501_es
CiscoCatalyst Sd-wan Manager Version19.0.0
CiscoCatalyst Sd-wan Manager Version19.0.1a
CiscoCatalyst Sd-wan Manager Version19.1.0
CiscoCatalyst Sd-wan Manager Version19.2.0
CiscoCatalyst Sd-wan Manager Version19.2.1
CiscoCatalyst Sd-wan Manager Version19.2.2
CiscoCatalyst Sd-wan Manager Version19.2.3
CiscoCatalyst Sd-wan Manager Version19.2.4
CiscoCatalyst Sd-wan Manager Version19.2.4.0.1
CiscoCatalyst Sd-wan Manager Version19.2.31
CiscoCatalyst Sd-wan Manager Version19.2.097
CiscoCatalyst Sd-wan Manager Version19.2.098
CiscoCatalyst Sd-wan Manager Version19.2.099
CiscoCatalyst Sd-wan Manager Version19.2.929
CiscoCatalyst Sd-wan Manager Version19.3.0
CiscoCatalyst Sd-wan Manager Version20.1.1
CiscoCatalyst Sd-wan Manager Version20.1.1.1
CiscoCatalyst Sd-wan Manager Version20.1.2
CiscoCatalyst Sd-wan Manager Version20.1.12
CiscoCatalyst Sd-wan Manager Version20.3.1
CiscoCatalyst Sd-wan Manager Version20.3.2
CiscoCatalyst Sd-wan Manager Version20.3.2.1
CiscoCatalyst Sd-wan Manager Version20.3.2.1_927
CiscoCatalyst Sd-wan Manager Version20.3.2.1_930
CiscoCatalyst Sd-wan Manager Version20.3.2_928
CiscoCatalyst Sd-wan Manager Version20.3.2_929
CiscoCatalyst Sd-wan Manager Version20.3.3
CiscoCatalyst Sd-wan Manager Version20.4.1
CiscoCatalyst Sd-wan Manager Version20.4.1.0.1
CiscoCatalyst Sd-wan Manager Version20.4.1.1
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.15% 0.359
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
psirt@cisco.com 6.5 2.8 3.6
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CWE-88 Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')

The product constructs a string for a command to be executed by a separate component in another control sphere, but it does not properly delimit the intended arguments, options, or switches within that command string.