Insufficiently protected credentials in Evolved Programmable Network (EPN) Manager and Cisco Prime Infrastructure - CVE-2021-34733
Published: September 1, 2021
Vulnerability identifier: #VU56246
CSH Severity: Low
CVSS v4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-34733
CWE-ID: CWE-522
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local user to gain access to sensitive information.
The vulnerability exists due to sensitive information is not sufficiently secured when it is stored on the system. A local user can create forged authentication requests and gain unauthorized access to the affected system.
Affected software
Evolved Programmable Network (EPN) Manager
Cisco Prime Infrastructure
Cisco Prime Infrastructure
How to mitigate CVE-2021-34733
Install updates from vendor's website.
Evolved Programmable Network (EPN) Manager - update to 5.0
Cisco Prime Infrastructure - update to 3.8.0
Cisco Prime Infrastructure - update to 3.8.0
External References
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-prime-info-disc-nTU9FJ2
- https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvs07217
- https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvz12884
- https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvz12896
- https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvs07213