CVE-2021-1589

MEDIUM

Cisco SD-WAN vManage Software - Privilege Escalation

Title source: llm

Description

A vulnerability in the disaster recovery feature of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to gain unauthorized access to user credentials. This vulnerability exists because access to API endpoints is not properly restricted. An attacker could exploit this vulnerability by sending a request to an API endpoint. A successful exploit could allow the attacker to gain unauthorized access to administrative credentials that could be used in further attacks.

Scores

CVSS v3 6.5
EPSS 0.0024
EPSS Percentile 47.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Classification

CWE
CWE-522 CWE-256
Status published

Affected Products (1)

cisco/sd-wan < 20.3.4

Timeline

Published Sep 23, 2021
Tracked Since Feb 18, 2026