Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2021-1438

Опубликовано: 06 мая 2021
Источник: nvd
CVSS3: 5.5
CVSS2: 2.1
EPSS Низкий

Описание

A vulnerability in Cisco Wide Area Application Services (WAAS) Software could allow an authenticated, local attacker to gain access to sensitive information on an affected device. The vulnerability is due to improper input validation and authorization of specific commands that a user can execute within the CLI. An attacker could exploit this vulnerability by authenticating to an affected device and issuing a specific set of commands. A successful exploit could allow the attacker to read arbitrary files that they originally did not have permissions to access.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:cisco:wide_area_application_services:*:*:*:*:*:*:*:*
Версия до 6.4.5a (включая)

EPSS

Процентиль: 14%
0.00046
Низкий

5.5 Medium

CVSS3

2.1 Low

CVSS2

Дефекты

CWE-668

Связанные уязвимости

github
больше 3 лет назад

A vulnerability in Cisco Wide Area Application Services (WAAS) Software could allow an authenticated, local attacker to gain access to sensitive information on an affected device. The vulnerability is due to improper input validation and authorization of specific commands that a user can execute within the CLI. An attacker could exploit this vulnerability by authenticating to an affected device and issuing a specific set of commands. A successful exploit could allow the attacker to read arbitrary files that they originally did not have permissions to access.

CVSS3: 5.5
fstec
почти 5 лет назад

Уязвимость программного пакета Cisco Wide Area Application Services Software (WAAS), связанная с раскрытием информации в ошибочной области данных, позволяющая нарушителю получить доступ к конфиденциальным данным

EPSS

Процентиль: 14%
0.00046
Низкий

5.5 Medium

CVSS3

2.1 Low

CVSS2

Дефекты

CWE-668