CVE-2021-1257
Cisco DNA Center Cross-Site Request Forgery Vulnerability
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
A vulnerability in the web-based management interface of Cisco DNA Center Software could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack to manipulate an authenticated user into executing malicious actions without their awareness or consent. The vulnerability is due to insufficient CSRF protections for the web-based management interface of an affected device. An attacker could exploit this vulnerability by persuading a web-based management user to follow a specially crafted link. A successful exploit could allow the attacker to perform arbitrary actions on the device with the privileges of the authenticated user. These actions include modifying the device configuration, disconnecting the user's session, and executing Command Runner commands.
Una vulnerabilidad en la interfaz de administración basada en web del Software Cisco DNA Center, podría permitir a un atacante no autenticado remoto conducir un ataque de tipo cross-site request forgery (CSRF) para manipular a un usuario autenticado para que ejecutar acciones maliciosas sin su conocimiento o consentimiento. La vulnerabilidad es debido a unas protecciones CSRF insuficientes para la interfaz de administración basada en web de un dispositivo afectado. Un atacante podría explotar esta vulnerabilidad persuadiendo a un usuario de administración basado en web para que siga un enlace especialmente diseñado. Una explotación con éxito podría permitir al atacante llevar a cabo acciones arbitrarias en el dispositivo con los privilegios del usuario autenticado. Estas acciones incluyen modificar la configuración del dispositivo, desconectar la sesión del usuario y ejecutar comandos de Command Runner
CVSS Scores
SSVC
- Decision:Track
Timeline
- 2020-11-13 CVE Reserved
- 2021-01-20 CVE Published
- 2024-10-07 EPSS Updated
- 2024-11-12 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-352: Cross-Site Request Forgery (CSRF)
CAPEC
References (2)
URL | Tag | Source |
---|---|---|
https://kc.mcafee.com/corporate/index?page=content&id=SB10382 | Third Party Advisory |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Mcafee Search vendor "Mcafee" | Agent Search vendor "Mcafee" for product "Agent" | < 5.7.6 Search vendor "Mcafee" for product "Agent" and version " < 5.7.6" | linux |
Affected
| in | Apple Search vendor "Apple" | Macos Search vendor "Apple" for product "Macos" | - | - |
Safe
|
Mcafee Search vendor "Mcafee" | Agent Search vendor "Mcafee" for product "Agent" | < 5.7.6 Search vendor "Mcafee" for product "Agent" and version " < 5.7.6" | linux |
Affected
| in | Linux Search vendor "Linux" | Linux Kernel Search vendor "Linux" for product "Linux Kernel" | - | - |
Safe
|
Mcafee Search vendor "Mcafee" | Agent Search vendor "Mcafee" for product "Agent" | < 5.7.6 Search vendor "Mcafee" for product "Agent" and version " < 5.7.6" | linux |
Affected
| in | Microsoft Search vendor "Microsoft" | Windows Search vendor "Microsoft" for product "Windows" | - | - |
Safe
|
Mcafee Search vendor "Mcafee" | Agent Search vendor "Mcafee" for product "Agent" | < 5.7.6 Search vendor "Mcafee" for product "Agent" and version " < 5.7.6" | macos |
Affected
| in | Apple Search vendor "Apple" | Macos Search vendor "Apple" for product "Macos" | - | - |
Safe
|
Mcafee Search vendor "Mcafee" | Agent Search vendor "Mcafee" for product "Agent" | < 5.7.6 Search vendor "Mcafee" for product "Agent" and version " < 5.7.6" | macos |
Affected
| in | Linux Search vendor "Linux" | Linux Kernel Search vendor "Linux" for product "Linux Kernel" | - | - |
Safe
|
Mcafee Search vendor "Mcafee" | Agent Search vendor "Mcafee" for product "Agent" | < 5.7.6 Search vendor "Mcafee" for product "Agent" and version " < 5.7.6" | macos |
Affected
| in | Microsoft Search vendor "Microsoft" | Windows Search vendor "Microsoft" for product "Windows" | - | - |
Safe
|
Mcafee Search vendor "Mcafee" | Agent Search vendor "Mcafee" for product "Agent" | < 5.7.6 Search vendor "Mcafee" for product "Agent" and version " < 5.7.6" | windows |
Affected
| in | Apple Search vendor "Apple" | Macos Search vendor "Apple" for product "Macos" | - | - |
Safe
|
Mcafee Search vendor "Mcafee" | Agent Search vendor "Mcafee" for product "Agent" | < 5.7.6 Search vendor "Mcafee" for product "Agent" and version " < 5.7.6" | windows |
Affected
| in | Linux Search vendor "Linux" | Linux Kernel Search vendor "Linux" for product "Linux Kernel" | - | - |
Safe
|
Mcafee Search vendor "Mcafee" | Agent Search vendor "Mcafee" for product "Agent" | < 5.7.6 Search vendor "Mcafee" for product "Agent" and version " < 5.7.6" | windows |
Affected
| in | Microsoft Search vendor "Microsoft" | Windows Search vendor "Microsoft" for product "Windows" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Dna Center Search vendor "Cisco" for product "Dna Center" | < 2.1.1.0 Search vendor "Cisco" for product "Dna Center" and version " < 2.1.1.0" | - |
Affected
|