CVE-2021-1535

A vulnerability in the cluster management interface of Cisco SD-WAN vManage Software could allow an unauthenticated, remote attacker to view sensitive information on an affected system. To be affected by this vulnerability, the Cisco SD-WAN vManage Software must be in cluster mode. This vulnerability is due to the absence of authentication for sensitive information in the cluster management interface. An attacker could exploit this vulnerability by sending a crafted request to the cluster management interface of an affected system. A successful exploit could allow the attacker to allow the attacker to view sensitive information on the affected system.
Configurations

Configuration 1 (hide)

cpe:2.3:a:cisco:sd-wan_vmanage:*:*:*:*:*:*:*:*

History

14 May 2021, 13:46

Type Values Removed Values Added
CPE cpe:2.3:a:cisco:sd-wan_vmanage:*:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : 5.0
v3 : 5.3
References (CISCO) https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-vmanageinfdis-LKrFpbv - (CISCO) https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-vmanageinfdis-LKrFpbv - Vendor Advisory

06 May 2021, 13:16

Type Values Removed Values Added
New CVE

Information

Published : 2021-05-06 13:15

Updated : 2023-12-10 13:55


NVD link : CVE-2021-1535

Mitre link : CVE-2021-1535

CVE.ORG link : CVE-2021-1535


JSON object : View

Products Affected

cisco

  • sd-wan_vmanage
CWE
CWE-497

Exposure of Sensitive System Information to an Unauthorized Control Sphere