CVE-2021-40126Self-generated Error Message Containing Sensitive Information in Cisco Umbrella Insights Virtual Appliance

Severity
4.3MEDIUMNVD
EPSS
0.2%
top 64.29%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 4
Latest updateMay 24

Description

A vulnerability in the web-based dashboard of Cisco Umbrella could allow an authenticated, remote attacker to perform an email enumeration attack against the Umbrella infrastructure. This vulnerability is due to an overly descriptive error message on the dashboard that appears when a user attempts to modify their email address when the new address already exists in the system. An attacker could exploit this vulnerability by attempting to modify the user's email address. A successful exploit coul

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:NExploitability: 2.8 | Impact: 1.4

Affected Packages1 packages

🔴Vulnerability Details

2
GHSA
GHSA-qh32-c3pp-x33g: A vulnerability in the web-based dashboard of Cisco Umbrella could allow an authenticated, remote attacker to perform an email enumeration attack agai2022-05-24
CVEList
Cisco Umbrella Email Enumeration Vulnerability2021-11-04

📋Vendor Advisories

1
Cisco
Cisco Umbrella Email Enumeration Vulnerability2021-11-03
CVE-2021-40126 — Cisco vulnerability | cvebase