PT-2021-1645 · Cisco · Cisco Connected Mobile Experiences
Published
2021-01-13
·
Updated
2022-08-05
·
CVE-2021-1143
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions:
Cisco Connected Mobile Experiences (CMX) (affected versions not specified)
Description:
The issue is related to a lack of authorization checks for certain API GET requests, which could allow an authenticated, remote attacker to enumerate users on the system. An attacker could exploit this by sending specific API GET requests to an affected device, potentially allowing them to enumerate users of the CMX system.
Recommendations:
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Incorrect Authorization
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Cisco Connected Mobile Experiences