#VU49532 Permissions, Privileges, and Access Controls in Cisco Connected Mobile Experiences - CVE-2021-1144
Published: January 13, 2021 / Updated: January 14, 2021
Cisco Connected Mobile Experiences
Cisco Systems, Inc
Description
The vulnerability allows a remote attacker to escalate privileges on the system.
The vulnerability exists due to incorrect handling of authorization checks for changing a password. A remote authenticated attacker can send a specially crafted HTTP request and alter the passwords of any user on the system, including an administrative user.