Server-Side Request Forgery (SSRF) in Cisco Data Center Network Manager - CVE-2021-1272

 

Server-Side Request Forgery (SSRF) in Cisco Data Center Network Manager - CVE-2021-1272

Published: January 20, 2021 / Updated: January 27, 2021


Vulnerability identifier: #VU50059
CSH Severity: Medium
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-1272
CWE-ID: CWE-918
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The disclosed vulnerability allows a remote attacker to perform SSRF attacks.

The vulnerability exists due to insufficient validation of user-supplied input in the session validation feature. A remote attacker can send a specially crafted HTTP request, trick the application to initiate requests to arbitrary systems and gain unauthorized access to the Device Manager application.


Affected software

Cisco Data Center Network Manager

How to mitigate CVE-2021-1272

Install updates from vendor's website.

Cisco Data Center Network Manager - update to 11.5.1

External References

Related Security Bulletins