CVE-2021-1589
MEDIUMCisco SD-WAN vManage Software - Privilege Escalation
Title source: llmDescription
A vulnerability in the disaster recovery feature of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to gain unauthorized access to user credentials. This vulnerability exists because access to API endpoints is not properly restricted. An attacker could exploit this vulnerability by sending a request to an API endpoint. A successful exploit could allow the attacker to gain unauthorized access to administrative credentials that could be used in further attacks.
Scores
CVSS v3
6.5
EPSS
0.0024
EPSS Percentile
47.1%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Classification
CWE
CWE-522
CWE-256
Status
published
Affected Products (1)
cisco/sd-wan
< 20.3.4
Timeline
Published
Sep 23, 2021
Tracked Since
Feb 18, 2026