CVE-2021-34782
published 2021-10-06CVE-2021-34782: A vulnerability in the API endpoints for Cisco DNA Center could allow an authenticated, remote attacker to gain access to sensitive information that should be…
PriorityP423medium4.3CVSS 3.1
AVNACLPRLUINSUCLINAN
EPSS
0.76%
51.0th percentile
A vulnerability in the API endpoints for Cisco DNA Center could allow an authenticated, remote attacker to gain access to sensitive information that should be restricted. The attacker must have valid device credentials. This vulnerability is due to improper access controls on API endpoints. An attacker could exploit the vulnerability by sending a specific API request to an affected application. A successful exploit could allow the attacker to obtain sensitive information about other users who are configured with higher privileges on the application.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | catalyst_center | < 2.2.2.5 | 2.2.2.5 |
| cisco | catalyst_center | >= 2.2.3.0 < 2.2.3.3 | 2.2.3.3 |
| cisco | cisco_digital_network_architecture_center | — | — |
| cisco | dna_center | — | — |
CVSS provenance
nvdv3.14.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:P/I:N/A:N
vendor_cisco4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco DNA Center Information Disclosure Vulnerability
vendor_cisco·2021-10-06·CVSS 4.3
CVE-2021-34782 [MEDIUM] CWE-202 Cisco DNA Center Information Disclosure Vulnerability
Cisco DNA Center Information Disclosure Vulnerability
A vulnerability in the API endpoints for Cisco DNA Center could allow an authenticated, remote attacker to gain access to sensitive information that should be restricted. The attacker must have valid device credentials.
This vulnerability is due to improper access controls on API endpoints. An attacker could exploit the vulnerability by sending a specific API request to an affected application. A successful exploit could allow the attacker to obtain sensitive information about other users who are configured with higher privileges on the application.
Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.
This advisory is available at the following link:https://sec.
Cisco
Cisco DNA Center Information Disclosure Vulnerability
vendor_cisco·CVSS 3.1
CVE-2021-34782 Cisco DNA Center Information Disclosure Vulnerability
CVE-2021-34782: Cisco DNA Center Information Disclosure Vulnerability
A vulnerability in the API endpoints for Cisco DNA Center could allow an authenticated, remote attacker to gain access to sensitive information that should be restricted. The attacker must have valid device credentials. This vulnerability is due to improper access controls on API endpoints. An attacker could exploit the vulnerability by sending a specific API request to an affected application. A successful exploit could allow the attacker to obtain sensitive information about other users who are configured with higher privileges on the application. Cisco has released software updates that address this vulnerability. There are no
CVSS: 3.1
CWE: CWE-202, CWE-202
Bug IDs: CSCvy18258
GHSA
Incorrect Authorization in Jenkins requests-plugin
ghsa·2022-07-01
CVE-2022-34782 [MEDIUM] CWE-863 Incorrect Authorization in Jenkins requests-plugin
Incorrect Authorization in Jenkins requests-plugin
An incorrect permission check in Jenkins requests-plugin Plugin 2.2.16 and earlier allows attackers with Overall/Read permission to view the list of pending requests. requests-plugin Plugin 2.2.17 requires Overall/Administer permission to view the list of pending requests.
This is basically the same vulnerability as [SECURITY-1995](https://www.jenkins.io/security/advisory/2021-06-30/#SECURITY-1995), whose fix was ineffective.
requests-plugin Plugin 2.2.17 requires Overall/Administer permission to view the list of pending requests.
GHSA
GHSA-5g3w-62hr-p464: A vulnerability in the API endpoints for Cisco DNA Center could allow an authenticated, remote attacker to gain access to sensitive information that s
ghsa_unreviewed·2022-05-24
CVE-2021-34782 [MEDIUM] CWE-202 GHSA-5g3w-62hr-p464: A vulnerability in the API endpoints for Cisco DNA Center could allow an authenticated, remote attacker to gain access to sensitive information that s
A vulnerability in the API endpoints for Cisco DNA Center could allow an authenticated, remote attacker to gain access to sensitive information that should be restricted. The attacker must have valid device credentials. This vulnerability is due to improper access controls on API endpoints. An attacker could exploit the vulnerability by sending a specific API request to an affected application. A successful exploit could allow the attacker to obtain sensitive information about other users who are configured with higher privileges on the application.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2021-10-06
Published