PT-2021-1645 · Cisco · Cisco Connected Mobile Experiences

Published

2021-01-13

·

Updated

2022-08-05

·

CVE-2021-1143

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions: Cisco Connected Mobile Experiences (CMX) (affected versions not specified)
Description: The issue is related to a lack of authorization checks for certain API GET requests, which could allow an authenticated, remote attacker to enumerate users on the system. An attacker could exploit this by sending specific API GET requests to an affected device, potentially allowing them to enumerate users of the CMX system.
Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Incorrect Authorization

Missing Authorization

Weakness Enumeration

Related Identifiers

BDU:2021-00301
CVE-2021-1143

Affected Products

Cisco Connected Mobile Experiences