#VU52913 Improper Authorization in Cisco SD-WAN vManage - CVE-2021-1535
Published: May 6, 2021
Cisco SD-WAN vManage
Cisco Systems, Inc
Description
The vulnerability allows a remote attacker to gain access to sensitive information.
The vulnerability exists due to absence of authentication for sensitive information in the cluster management interface. A remote non-authenticated attacker can send a specially crafted request to the cluster management interface and gain access to sensitive information.
To exploit the vulnerability the vManage Software must be in cluster mode.