CVE-2021-1600

HIGH

Cisco Intersight Virtual Appliance - Unauthenticated Sensitive Internal Service Access via External Management Interface

Title source: llm
STIX 2.1

Description

Multiple vulnerabilities in Cisco Intersight Virtual Appliance could allow an unauthenticated, adjacent attacker to access sensitive internal services from an external interface. These vulnerabilities are due to insufficient restrictions for IPv4 or IPv6 packets that are received on the external management interface. An attacker could exploit these vulnerabilities by sending specific traffic to this interface on an affected device. A successful exploit could allow the attacker to access sensitive internal services and make configuration changes on the affected device.

References (1)

Core 1
Core References

Scores

CVSS v3 8.3
EPSS 0.0011
EPSS Percentile 28.3%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-284
Status published
Products (1)
cisco/intersight_virtual_appliance 1.0\(1\)
Published Jul 22, 2021
Tracked Since Feb 18, 2026