CVE-2021-1589
Cisco SD-WAN vManage Software Disaster Recovery Feature Password Exposure Vulnerability
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
A vulnerability in the disaster recovery feature of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to gain unauthorized access to user credentials. This vulnerability exists because access to API endpoints is not properly restricted. An attacker could exploit this vulnerability by sending a request to an API endpoint. A successful exploit could allow the attacker to gain unauthorized access to administrative credentials that could be used in further attacks.
Una vulnerabilidad en la funcionalidad disaster recovery de Cisco SD-WAN vManage Software podría permitir a un atacante remoto autenticado conseguir acceso no autorizado a las credenciales del usuario. Esta vulnerabilidad se presenta porque el acceso a los endpoints de la API no está debidamente restringido. Un atacante podría explotar esta vulnerabilidad mediante el envío de una petición a un endpoint de la API. Una explotación con éxito podría permitir al atacante conseguir acceso no autorizado a credenciales administrativas que podrían ser usadas en otros ataques
CVSS Scores
SSVC
- Decision:Track
Timeline
- 2020-11-13 CVE Reserved
- 2021-09-23 CVE Published
- 2023-12-15 EPSS Updated
- 2024-11-07 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-256: Plaintext Storage of a Password
- CWE-522: Insufficiently Protected Credentials
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sd-wan-credentials-ydYfskzZ | 2023-11-07 |
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Cisco Search vendor "Cisco" | Sd-wan Search vendor "Cisco" for product "Sd-wan" | >= 20.3 < 20.3.4 Search vendor "Cisco" for product "Sd-wan" and version " >= 20.3 < 20.3.4" | - |
Affected
| ||||||
Cisco Search vendor "Cisco" | Sd-wan Search vendor "Cisco" for product "Sd-wan" | >= 20.4 < 20.4.2 Search vendor "Cisco" for product "Sd-wan" and version " >= 20.4 < 20.4.2" | - |
Affected
| ||||||
Cisco Search vendor "Cisco" | Sd-wan Search vendor "Cisco" for product "Sd-wan" | >= 20.5 < 20.5.2 Search vendor "Cisco" for product "Sd-wan" and version " >= 20.5 < 20.5.2" | - |
Affected
| ||||||
Cisco Search vendor "Cisco" | Sd-wan Search vendor "Cisco" for product "Sd-wan" | >= 20.6 < 20.6.1 Search vendor "Cisco" for product "Sd-wan" and version " >= 20.6 < 20.6.1" | - |
Affected
|