PT-2021-5326 · Cisco · Cisco Sd-Wan Vmanage

Published

2021-09-22

·

Updated

2023-10-16

·

CVE-2021-34712

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Cisco SD-WAN vManage Software (affected versions not specified)
Description The issue exists due to insufficient input validation by the web-based management interface of Cisco SD-WAN vManage Software. An attacker could exploit this by sending crafted HTTP requests to the interface of an affected system, potentially allowing them to obtain sensitive information. This could be done through cypher query language injection attacks.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

Weakness Enumeration

Related Identifiers

BDU:2021-06154
CVE-2021-34712

Affected Products

Cisco Sd-Wan Vmanage