PT-2021-3257 · Cisco · Cisco Sd-Wan Vmanage

Published

2021-05-05

·

Updated

2022-10-21

·

CVE-2021-1515

CVSS v3.1

4.3

Medium

VectorAV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Cisco SD-WAN vManage Software (affected versions not specified)
Description The issue is related to insufficient access control in the Cisco SD-WAN vManage web interface, allowing a remote attacker to gain unauthorized access to protected information by sending specially crafted requests. This vulnerability is due to improper access controls on API endpoints when Cisco SD-WAN vManage Software is running in multi-tenant mode. An attacker with access to a device managed in the multi-tenant environment could exploit this vulnerability by sending a request to an affected API endpoint on the vManage system, potentially gaining access to sensitive information, including hashed credentials that could be used in future attacks.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Access Control

Weakness Enumeration

Related Identifiers

BDU:2021-02990
CVE-2021-1515

Affected Products

Cisco Sd-Wan Vmanage