PT-2021-3257 · Cisco · Cisco Sd-Wan Vmanage
Published
2021-05-05
·
Updated
2022-10-21
·
CVE-2021-1515
CVSS v3.1
4.3
Medium
| Vector | AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Cisco SD-WAN vManage Software (affected versions not specified)
Description
The issue is related to insufficient access control in the Cisco SD-WAN vManage web interface, allowing a remote attacker to gain unauthorized access to protected information by sending specially crafted requests. This vulnerability is due to improper access controls on API endpoints when Cisco SD-WAN vManage Software is running in multi-tenant mode. An attacker with access to a device managed in the multi-tenant environment could exploit this vulnerability by sending a request to an affected API endpoint on the vManage system, potentially gaining access to sensitive information, including hashed credentials that could be used in future attacks.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Improper Access Control
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cisco Sd-Wan Vmanage