CVE-2021-1144
Cisco Connected Mobile Experiences Privilege Escalation Vulnerability
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
A vulnerability in Cisco Connected Mobile Experiences (CMX) could allow a remote, authenticated attacker without administrative privileges to alter the password of any user on an affected system. The vulnerability is due to incorrect handling of authorization checks for changing a password. An authenticated attacker without administrative privileges could exploit this vulnerability by sending a modified HTTP request to an affected device. A successful exploit could allow the attacker to alter the passwords of any user on the system, including an administrative user, and then impersonate that user.
Una vulnerabilidad en Cisco Connected Mobile Experiences (CMX), podría permitir a un atacante autenticado remoto sin privilegios administrativos alterar la contraseña de cualquier usuario en un sistema afectado. La vulnerabilidad es debido al manejo incorrecto de las comprobaciones de autorización para cambiar una contraseña. Un atacante autenticado sin privilegios administrativos podría explotar esta vulnerabilidad mediante el envío de una petición HTTP modificada hacia un dispositivo afectado. Una explotación con éxito podría permitir al atacante alterar las contraseñas de cualquier usuario del sistema, incluyendo un usuario administrativo, y luego hacerse pasar por ese usuario.
CVSS Scores
SSVC
- Decision:Track*
Timeline
- 2020-11-13 CVE Reserved
- 2021-01-13 CVE Published
- 2023-04-07 EPSS Updated
- 2024-11-12 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-863: Incorrect Authorization
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cmxpe-75Asy9k | 2023-11-07 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Cisco Search vendor "Cisco" | Connected Mobile Experiences Search vendor "Cisco" for product "Connected Mobile Experiences" | 10.6.0 Search vendor "Cisco" for product "Connected Mobile Experiences" and version "10.6.0" | - |
Affected
| ||||||
Cisco Search vendor "Cisco" | Connected Mobile Experiences Search vendor "Cisco" for product "Connected Mobile Experiences" | 10.6.1 Search vendor "Cisco" for product "Connected Mobile Experiences" and version "10.6.1" | - |
Affected
| ||||||
Cisco Search vendor "Cisco" | Connected Mobile Experiences Search vendor "Cisco" for product "Connected Mobile Experiences" | 10.6.2 Search vendor "Cisco" for product "Connected Mobile Experiences" and version "10.6.2" | - |
Affected
|