CVE-2021-1481
CVSS 3.1 Score 4.3 of 10 (medium)
Details
Published Nov 15, 2024
CWE ID 943
Summary
CVE-2021-1481 is a vulnerability affecting Cisco SD-WAN vManage Software. It allows authenticated, remote attackers to execute Cypher query language injection attacks, which could result in obtaining sensitive information. The issue stems from insufficient input validation in the web-based management interface. Attackers can exploit this vulnerability by sending crafted HTTP requests. Cisco has released software updates to mitigate this risk, and currently, no workarounds are available.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Cisco Catalyst SD-WAN Manager
Affected Vendors
- Cisco Systems Inc