Vulnerability Name: | CVE-2021-1305 (CCN-195328) | ||||||||||||
Assigned: | 2020-11-13 | ||||||||||||
Published: | 2021-01-20 | ||||||||||||
Updated: | 2022-09-20 | ||||||||||||
Summary: | Multiple vulnerabilities in the web-based management interface of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to bypass authorization and modify the configuration of an affected system, gain access to sensitive information, and view information that they are not authorized to access. For more information about these vulnerabilities, see the Details section of this advisory. | ||||||||||||
CVSS v3 Severity: | 4.3 Medium (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N) 3.8 Low (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N/E:U/RL:O/RC:C)
3.8 Low (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N/E:U/RL:O/RC:C)
| ||||||||||||
CVSS v2 Severity: | 4.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:S/C:P/I:N/A:N)
| ||||||||||||
Vulnerability Type: | CWE-863 | ||||||||||||
Vulnerability Consequences: | Obtain Information | ||||||||||||
References: | Source: MITRE Type: CNA CVE-2021-1305 Source: XF Type: UNKNOWN cisco-cve20211305-info-disc(195328) Source: CCN Type: Cisco Security Advisory cisco-sa-sdwan-abyp-TnGFHrS Cisco SD-WAN vManage Authorization Bypass Vulnerabilities Source: CISCO Type: Vendor Advisory 20210120 Cisco SD-WAN vManage Authorization Bypass Vulnerabilities | ||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration 2: Denotes that component is vulnerable | ||||||||||||
BACK |