PT-2021-1645 · Cisco · Cisco Connected Mobile Experiences

CVE-2021-1143

·

Published

2021-01-13

·

Updated

2022-08-05

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions: Cisco Connected Mobile Experiences (CMX) (affected versions not specified)
Description: The issue is related to a lack of authorization checks for certain API GET requests, which could allow an authenticated, remote attacker to enumerate users on the system. An attacker could exploit this by sending specific API GET requests to an affected device, potentially allowing them to enumerate users of the CMX system.
Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Incorrect Authorization

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2021-00301
CVE-2021-1143

Affected Products

Cisco Connected Mobile Experiences