CVE-2021-1589

MEDIUM

Cisco SD-WAN vManage Software - Privilege Escalation

Title source: llm
STIX 2.1

Description

A vulnerability in the disaster recovery feature of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to gain unauthorized access to user credentials. This vulnerability exists because access to API endpoints is not properly restricted. An attacker could exploit this vulnerability by sending a request to an API endpoint. A successful exploit could allow the attacker to gain unauthorized access to administrative credentials that could be used in further attacks.

Scores

CVSS v3 6.5
EPSS 0.0024
EPSS Percentile 47.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-522 CWE-256
Status published
Products (1)
cisco/sd-wan 20.3 - 20.3.4
Published Sep 23, 2021
Tracked Since Feb 18, 2026