CVE-2021-1248
Published on: 01/20/2021 12:00:00 AM UTC
Last Modified on: 03/23/2021 11:28:55 PM UTC
CVE-2021-1248 - advisory for cisco-sa-dcnm-sql-inj-OAQOObP
Source: Mitre Source: NIST CVE.ORG Print: PDF
Certain versions of Data Center Network Manager from Cisco contain the following vulnerability:
Multiple vulnerabilities in certain REST API endpoints of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote attacker to execute arbitrary SQL commands on an affected device. For more information about these vulnerabilities, see the Details section of this advisory.
- CVE-2021-1248 has been assigned by
[email protected] to track the vulnerability - currently rated as HIGH severity.
- The Cisco Product Security Incident Response Team (PSIRT) is not aware of any public announcements or malicious use of the vulnerabilities that are described in this advisory.
- Affected Vendor/Software:
Cisco - Cisco Data Center Network Manager version n/a
CVSS3 Score: 7.2 - HIGH
Attack Vector ⓘ |
Attack Complexity |
Privileges Required |
User Interaction |
---|---|---|---|
NETWORK | LOW | HIGH | NONE |
Scope | Confidentiality Impact |
Integrity Impact |
Availability Impact |
UNCHANGED | HIGH | HIGH | HIGH |
CVSS2 Score: 6.5 - MEDIUM
Access Vector ⓘ |
Access Complexity |
Authentication |
---|---|---|
NETWORK | LOW | SINGLE |
Confidentiality Impact |
Integrity Impact |
Availability Impact |
PARTIAL | PARTIAL | PARTIAL |
CVE References
Description | Tags ⓘ | Link |
---|---|---|
Cisco Data Center Network Manager SQL Injection Vulnerabilities | Vendor Advisory tools.cisco.com text/html |
![]() |
There are currently no QIDs associated with this CVE
Known Affected Configurations (CPE V2.3)
Type | Vendor | Product | Version | Update | Edition | Language |
---|---|---|---|---|---|---|
Application | Cisco | Data Center Network Manager | All | All | All | All |
Application | Cisco | Data Center Network Manager | All | All | All | All |
- cpe:2.3:a:cisco:data_center_network_manager:*:*:*:*:*:*:*:*:
- cpe:2.3:a:cisco:data_center_network_manager:*:*:*:*:*:*:*:*:
No vendor comments have been submitted for this CVE