Vulnerabilities > CVE-2021-1305 - Incorrect Authorization vulnerability in Cisco products

047910
CVSS 4.3 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
LOW
Confidentiality impact
LOW
Integrity impact
NONE
Availability impact
NONE
network
low complexity
cisco
CWE-863

Summary

Multiple vulnerabilities in the web-based management interface of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to bypass authorization and modify the configuration of an affected system, gain access to sensitive information, and view information that they are not authorized to access. For more information about these vulnerabilities, see the Details section of this advisory.

Vulnerable Configurations

Part Description Count
OS
Cisco
52
Hardware
Cisco
8
Application
Cisco
1

Common Weakness Enumeration (CWE)