#VU52912 Improper Authorization in Cisco SD-WAN vManage - CVE-2021-1234
Published: May 6, 2021
Cisco SD-WAN vManage
Cisco Systems, Inc
Description
The vulnerability allows a remote attacker to gain access to sensitive information.
The vulnerability exists due to absence of authentication for sensitive information in the cluster management interface. A remote attacker can send a specially crafted request to the management interface and gain access to sensitive information.
Note, successful exploitation of the vulnerability requires that vManage software is in cluster mode.