CVE-2021-1135Incomplete List of Disallowed Inputs in Cisco Data Center Network Manager

Severity
4.3MEDIUMNVD
CNA4.6
EPSS
0.2%
top 62.06%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 20
Latest updateMay 24

Description

Multiple vulnerabilities in the REST API endpoint of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote attacker to view, modify, and delete data without proper authorization. For more information about these vulnerabilities, see the Details section of this advisory.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:NExploitability: 2.8 | Impact: 1.4

Affected Packages2 packages

🔴Vulnerability Details

2
GHSA
GHSA-8xff-w72m-pxvj: Multiple vulnerabilities in the REST API endpoint of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote attacker to view, m2022-05-24
CVEList
Cisco Data Center Network Manager REST API Vulnerabilities2021-01-20

📋Vendor Advisories

1
Cisco
Cisco Data Center Network Manager REST API Vulnerabilities2021-01-20
CVE-2021-1135 — Incomplete List of Disallowed Inputs | cvebase