Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2021-34782

Опубликовано: 06 окт. 2021
Источник: nvd
CVSS3: 4.3
CVSS2: 4
EPSS Низкий

Описание

A vulnerability in the API endpoints for Cisco DNA Center could allow an authenticated, remote attacker to gain access to sensitive information that should be restricted. The attacker must have valid device credentials. This vulnerability is due to improper access controls on API endpoints. An attacker could exploit the vulnerability by sending a specific API request to an affected application. A successful exploit could allow the attacker to obtain sensitive information about other users who are configured with higher privileges on the application.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:cisco:catalyst_center:*:*:*:*:*:*:*:*
Версия до 2.2.2.5 (исключая)
cpe:2.3:a:cisco:catalyst_center:*:*:*:*:*:*:*:*
Версия от 2.2.3.0 (включая) до 2.2.3.3 (исключая)

EPSS

Процентиль: 51%
0.00277
Низкий

4.3 Medium

CVSS3

4 Medium

CVSS2

Дефекты

CWE-202
NVD-CWE-Other

Связанные уязвимости

CVSS3: 4.3
github
больше 3 лет назад

A vulnerability in the API endpoints for Cisco DNA Center could allow an authenticated, remote attacker to gain access to sensitive information that should be restricted. The attacker must have valid device credentials. This vulnerability is due to improper access controls on API endpoints. An attacker could exploit the vulnerability by sending a specific API request to an affected application. A successful exploit could allow the attacker to obtain sensitive information about other users who are configured with higher privileges on the application.

CVSS3: 4.3
fstec
больше 4 лет назад

Уязвимость веб-интерфейса центра управления сетью Cisco DNA Center, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

EPSS

Процентиль: 51%
0.00277
Низкий

4.3 Medium

CVSS3

4 Medium

CVSS2

Дефекты

CWE-202
NVD-CWE-Other