CVE-2021-1286
published 2021-01-20CVE-2021-1286: Multiple vulnerabilities in the web-based management interface of Cisco Data Center Network Manager (DCNM) could allow a remote attacker with network-operator…
PriorityP427medium6.1CVSS 3.1
AVNACLPRNUIRSCCLILAN
EPSS
0.94%
56.8th percentile
Multiple vulnerabilities in the web-based management interface of Cisco Data Center Network Manager (DCNM) could allow a remote attacker with network-operator privileges to conduct a cross-site scripting (XSS) attack or a reflected file download (RFD) attack against a user of the interface. For more information about these vulnerabilities, see the Details section of this advisory.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | cisco_data_center_network_manager | — | — |
| cisco | data_center_network_manager | < 11.5\(1\) | 11.5\(1\) |
| cisco | data_center_network_manager | — | — |
CVSS provenance
nvdv3.16.1MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
vendor_cisco6.5MEDIUM
vendor_redhat5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
nodejs-url-parse: mishandling certain uses of backslash may lead to confidentiality compromise
vendor_redhat·2021-02-22·CVSS 5.3
CVE-2021-27515 [MEDIUM] CWE-1286 nodejs-url-parse: mishandling certain uses of backslash may lead to confidentiality compromise
nodejs-url-parse: mishandling certain uses of backslash may lead to confidentiality compromise
url-parse before 1.5.0 mishandles certain uses of backslash such as http:\/ and interprets the URI as a relative path.
An input validation flaw exists in the node.js-url-parse, which results in the URL being incorrectly set to the document location protocol instead of the URL being passed as an argument. This flaw allows an attacker to bypass security checks on URLs. The highest threat from this vulnerability is to integrity. This is an incomplete fix for CVE-2020-8124.
Package: servicemesh-grafana (OpenShift Service Mesh 2.0) - Not affected
Package: servicemesh-prometheus (OpenShift Service Mesh 2.0) - Not affected
Package: rhacm2/console-rhel8 (Red Hat Advanced Cluster Management for Kuber
Cisco
Cisco Data Center Network Manager Vulnerabilities
vendor_cisco·2021-01-20·CVSS 6.5
CVE-2021-1249 [MEDIUM] CWE-20 Cisco Data Center Network Manager Vulnerabilities
Cisco Data Center Network Manager Vulnerabilities
Multiple vulnerabilities in the web-based management interface of Cisco Data Center Network Manager (DCNM) could allow a remote attacker with network-operator privileges to conduct a cross-site scripting (XSS) attack or a reflected file download (RFD) attack against a user of the interface.
For more information about these vulnerabilities, see the Details section of this advisory.
Cisco has released software updates that address these vulnerabilities. There are no workarounds that address these vulnerabilities.
This advisory is available at the following link:https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-dcnm-xss-vulns-GuUJ39gh
Cisco
Cisco Data Center Network Manager Vulnerabilities
vendor_cisco·CVSS 3.1
CVE-2021-1286 Cisco Data Center Network Manager Vulnerabilities
CVE-2021-1286: Cisco Data Center Network Manager Vulnerabilities
Multiple vulnerabilities in the web-based management interface of Cisco Data Center Network Manager (DCNM) could allow a remote attacker with network-operator privileges to conduct a cross-site scripting (XSS) attack or a reflected file download (RFD) attack against a user of the interface. For more information about these vulnerabilities, see the
CVSS: 3.1
CWE: CWE-20, CWE-79, CWE-20, CWE-79
Bug IDs: CSCvu50101, CSCvu68933, CSCvv00638, CSCvu50101, CSCvu68933
GHSA
GHSA-37gp-666w-35h8: Multiple vulnerabilities in the web-based management interface of Cisco Data Center Network Manager (DCNM) could allow a remote attacker with network-
ghsa_unreviewed·2022-05-24
CVE-2021-1286 [MEDIUM] CWE-20 GHSA-37gp-666w-35h8: Multiple vulnerabilities in the web-based management interface of Cisco Data Center Network Manager (DCNM) could allow a remote attacker with network-
Multiple vulnerabilities in the web-based management interface of Cisco Data Center Network Manager (DCNM) could allow a remote attacker with network-operator privileges to conduct a cross-site scripting (XSS) attack or a reflected file download (RFD) attack against a user of the interface.
For more information about these vulnerabilities, see the Details section of this advisory.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2021-01-20
Published