Severity
8.8HIGH
EPSS
7.2%
top 8.42%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 20
Latest updateMay 24

Description

Multiple vulnerabilities in the web UI of Cisco Smart Software Manager Satellite could allow an unauthenticated, remote attacker to execute arbitrary commands on the underlying operating system. For more information about these vulnerabilities, see the Details section of this advisory.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

🔴Vulnerability Details

2
GHSA
GHSA-x8m3-65hg-3375: Multiple vulnerabilities in the web UI of Cisco Smart Software Manager Satellite could allow an unauthenticated, remote attacker to execute arbitrary2022-05-24
CVEList
Cisco Smart Software Manager Satellite Web UI Command Injection Vulnerabilities2021-01-20

📋Vendor Advisories

1
Cisco
Cisco Smart Software Manager Satellite Web UI Command Injection Vulnerabilities2021-01-20
CVE-2021-1139 (HIGH CVSS 8.8) | Multiple vulnerabilities in the web | cvebase.io