#VU51227 Improper Authorization in Cisco SD-WAN vManage - CVE-2021-1464

 

#VU51227 Improper Authorization in Cisco SD-WAN vManage - CVE-2021-1464

Published: March 4, 2021


Vulnerability identifier: #VU51227
Vulnerability risk: Medium
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Green
CVE-ID: CVE-2021-1464
CWE-ID: CWE-285
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vulnerable software:
Cisco SD-WAN vManage
Software vendor:
Cisco Systems, Inc

Description

The vulnerability allows a remote attacker to bypass authorization checks.

The vulnerability exists due to insufficient authorization checks. A remote authenticated attacker can send specially crafted requests to bypass authorization checks and gain restricted access to the configuration data of the target system.


Remediation

Install updates from vendor's website.

External links