CVE-2021-1483

CVSS 3.1 Score 6.4 of 10 (medium)

Details

Published Nov 15, 2024
CWE ID 611

Summary

CVE-2021-1483 is a vulnerability affecting the web UI of Cisco SD-WAN vManage Software. It allows authenticated, remote attackers to gain read and write access to sensitive information stored on affected systems. The issue arises due to the software's improper handling of XML External Entity (XXE) entries during XML file parsing. An attacker can exploit this flaw by persuading a user to import a specially crafted XML file containing malicious entries. Consequences of a successful attack include the ability to read and write files within the application. Cisco has released software updates to mitigate this vulnerability, and currently, no workarounds are available.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Cisco Catalyst SD-WAN Manager

Affected Vendors

  • Cisco Systems Inc