#VU57946 Information disclosure in Cisco Umbrella - CVE-2021-40126
Published: November 4, 2021
Cisco Umbrella
Cisco Systems, Inc
Description
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to an overly descriptive error message on the dashboard that appears when a user attempts to modify their email address when the new address already exists in the system. A remote authenticated attacker can gain unauthorized access to sensitive information on the system.