CVE-2021-1481

CVSS 3.1 Score 4.3 of 10 (medium)

Details

Published Nov 15, 2024
CWE ID 943

Summary

CVE-2021-1481 is a vulnerability affecting Cisco SD-WAN vManage Software. It allows authenticated, remote attackers to execute Cypher query language injection attacks, which could result in obtaining sensitive information. The issue stems from insufficient input validation in the web-based management interface. Attackers can exploit this vulnerability by sending crafted HTTP requests. Cisco has released software updates to mitigate this risk, and currently, no workarounds are available.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Cisco Catalyst SD-WAN Manager

Affected Vendors

  • Cisco Systems Inc