CVE-2021-1234

MEDIUM

Cisco SD-WAN vManage - Info Disclosure

Title source: llm
STIX 2.1

Description

A vulnerability in the cluster management interface of Cisco SD-WAN vManage Software could allow an unauthenticated, remote attacker to view sensitive information on an affected system. To be affected by this vulnerability, the vManage software must be in cluster mode. This vulnerability is due to the absence of authentication for sensitive information in the cluster management interface. An attacker could exploit this vulnerability by sending a crafted request to the cluster management interface of an affected system. A successful exploit could allow the attacker to view sensitive information on the affected system.Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.

Scores

CVSS v3 5.3
EPSS 0.0022
EPSS Percentile 43.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-497
Status published
Products (48)
cisco/catalyst_sd-wan_manager 17.2.4
cisco/catalyst_sd-wan_manager 17.2.5
cisco/catalyst_sd-wan_manager 17.2.6
cisco/catalyst_sd-wan_manager 17.2.7
cisco/catalyst_sd-wan_manager 17.2.8
cisco/catalyst_sd-wan_manager 17.2.9
cisco/catalyst_sd-wan_manager 17.2.10
cisco/catalyst_sd-wan_manager 18.2.0
cisco/catalyst_sd-wan_manager 18.3.0
cisco/catalyst_sd-wan_manager 18.3.1
... and 38 more
Published Nov 18, 2024
Tracked Since Feb 18, 2026