CVE-2021-1396
Cisco Application Services Engine Unauthorized Access Vulnerabilities
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Multiple vulnerabilities in Cisco Application Services Engine could allow an unauthenticated, remote attacker to gain privileged access to host-level operations or to learn device-specific information, create diagnostic files, and make limited configuration changes. For more information about these vulnerabilities, see the Details section of this advisory.
Múltiples vulnerabilidades en Cisco Application Services Engine podrían permitir a un atacante remoto no autenticado conseguir acceso privilegiado a operaciones a nivel de host o aprender información específica del dispositivo, crear archivos de diagnóstico y realizar cambios de configuración limitados. Para más información sobre estas vulnerabilidades, consulte la sección Detalles de este aviso
CVSS Scores
SSVC
- Decision:Attend
Timeline
- 2020-11-13 CVE Reserved
- 2021-02-24 CVE Published
- 2024-02-28 EPSS Updated
- 2024-11-08 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-306: Missing Authentication for Critical Function
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Cisco Search vendor "Cisco" | Application Services Engine Search vendor "Cisco" for product "Application Services Engine" | >= 1.1 < 1.1\(3e\) Search vendor "Cisco" for product "Application Services Engine" and version " >= 1.1 < 1.1\(3e\)" | - |
Affected
| ||||||
Cisco Search vendor "Cisco" | Application Policy Infrastructure Controller Search vendor "Cisco" for product "Application Policy Infrastructure Controller" | 1.1.3 Search vendor "Cisco" for product "Application Policy Infrastructure Controller" and version "1.1.3" | c |
Affected
| ||||||
Cisco Search vendor "Cisco" | Application Policy Infrastructure Controller Search vendor "Cisco" for product "Application Policy Infrastructure Controller" | 1.1.3 Search vendor "Cisco" for product "Application Policy Infrastructure Controller" and version "1.1.3" | d |
Affected
|