CVE-2021-1130
published 2021-01-13CVE-2021-1130: A vulnerability in the web-based management interface of Cisco DNA Center software could allow an authenticated, remote attacker to conduct a cross-site…
PriorityP420medium4.8CVSS 3.1
AVNACLPRHUIRSCCLILAN
EPSS
0.82%
53.0th percentile
A vulnerability in the web-based management interface of Cisco DNA Center software could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface of an affected device. The vulnerability exists because the web-based management interface does not properly validate user-supplied input. An attacker could exploit this vulnerability by persuading a user to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the interface or access sensitive, browser-based information. To exploit this vulnerability, an attacker would need to have administrative credentials on the affected device.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | catalyst_center | < 2.2.1.0 | 2.2.1.0 |
| cisco | cisco_digital_network_architecture_center | — | — |
| cisco | dna_center | — | — |
| flutterchina | dio | >= 0 < 5.0.0 | 5.0.0 |
CVSS provenance
nvdv3.14.8MEDIUMCVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
nvdv2.03.5LOWAV:N/AC:M/Au:S/C:N/I:P/A:N
ghsa6.1MEDIUM
vendor_cisco4.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco DNA Center Cross-Site Scripting Vulnerability
vendor_cisco·2021-01-13·CVSS 4.8
CVE-2021-1130 [MEDIUM] CWE-79 Cisco DNA Center Cross-Site Scripting Vulnerability
Cisco DNA Center Cross-Site Scripting Vulnerability
A vulnerability in the web-based management interface of Cisco DNA Center software could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface of an affected device.
The vulnerability exists because the web-based management interface does not properly validate user-supplied input. An attacker could exploit this vulnerability by persuading a user to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the interface or access sensitive, browser-based information. To exploit this vulnerability, an attacker would need to have administrative credentials on the affected device.
There are no workarounds that addres
Cisco
Cisco DNA Center Cross-Site Scripting Vulnerability
vendor_cisco·CVSS 3.1
CVE-2021-1130 Cisco DNA Center Cross-Site Scripting Vulnerability
CVE-2021-1130: Cisco DNA Center Cross-Site Scripting Vulnerability
A vulnerability in the web-based management interface of Cisco DNA Center software could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface of an affected device. The vulnerability exists because the web-based management interface does not properly validate user-supplied input. An attacker could exploit this vulnerability by persuading a user to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the interface or access sensitive, browser-based information. To exploit this vulnerability, an attacker would need to have administrative credentials on the affected device. There are no
CVSS: 3.1
GHSA
dio vulnerable to CRLF injection with HTTP method string
ghsa·2023-03-21·CVSS 6.1
CVE-2021-31402 [MEDIUM] CWE-93 dio vulnerable to CRLF injection with HTTP method string
dio vulnerable to CRLF injection with HTTP method string
### Impact
The dio package 4.0.0 for Dart allows CRLF injection if the attacker controls the HTTP method string, a different vulnerability than CVE-2020-35669.
### Patches
The vulnerability has been resolved by https://github.com/cfug/dio/commit/927f79e93ba39f3c3a12c190624a55653d577984, and included since v5.0.0.
### Workarounds
Cherry-pick the commit to your own fork can resolves the vulberability too.
### References
- https://nvd.nist.gov/vuln/detail/CVE-2021-31402
- https://osv.dev/GHSA-jwpw-q68h-r678
- https://github.com/cfug/dio/issues/1130
- https://github.com/cfug/dio/issues/1752
GHSA
GHSA-6xfc-46hj-r3cf: A vulnerability in the web-based management interface of Cisco DNA Center software could allow an authenticated, remote attacker to conduct a cross-si
ghsa_unreviewed·2022-05-24
CVE-2021-1130 [MEDIUM] CWE-79 GHSA-6xfc-46hj-r3cf: A vulnerability in the web-based management interface of Cisco DNA Center software could allow an authenticated, remote attacker to conduct a cross-si
A vulnerability in the web-based management interface of Cisco DNA Center software could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface of an affected device. The vulnerability exists because the web-based management interface does not properly validate user-supplied input. An attacker could exploit this vulnerability by persuading a user to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the interface or access sensitive, browser-based information. To exploit this vulnerability, an attacker would need to have administrative credentials on the affected device.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2021-01-13
Published