CVE-2021-1255
Published on: 01/20/2021 12:00:00 AM UTC
Last Modified on: 03/23/2021 11:28:56 PM UTC
CVE-2021-1255 - advisory for cisco-sa-dcnm-api-path-TpTApx2p
Source: Mitre Source: NIST CVE.ORG Print: PDF
Certain versions of Data Center Network Manager from Cisco contain the following vulnerability:
Multiple vulnerabilities in the REST API endpoint of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote attacker to view, modify, and delete data without proper authorization. For more information about these vulnerabilities, see the Details section of this advisory.
- CVE-2021-1255 has been assigned by
[email protected] to track the vulnerability - currently rated as MEDIUM severity.
- The Cisco Product Security Incident Response Team (PSIRT) is not aware of any public announcements or malicious use of the vulnerabilities that are described in this advisory.
- Affected Vendor/Software:
Cisco - Cisco Data Center Network Manager version n/a
CVSS3 Score: 5.4 - MEDIUM
Attack Vector ⓘ |
Attack Complexity |
Privileges Required |
User Interaction |
---|---|---|---|
NETWORK | LOW | LOW | NONE |
Scope | Confidentiality Impact |
Integrity Impact |
Availability Impact |
UNCHANGED | LOW | LOW | NONE |
CVSS2 Score: 5.5 - MEDIUM
Access Vector ⓘ |
Access Complexity |
Authentication |
---|---|---|
NETWORK | LOW | SINGLE |
Confidentiality Impact |
Integrity Impact |
Availability Impact |
PARTIAL | PARTIAL | NONE |
CVE References
Description | Tags ⓘ | Link |
---|---|---|
Cisco Data Center Network Manager REST API Vulnerabilities | Vendor Advisory tools.cisco.com text/html |
![]() |
There are currently no QIDs associated with this CVE
Known Affected Configurations (CPE V2.3)
Type | Vendor | Product | Version | Update | Edition | Language |
---|---|---|---|---|---|---|
Application | Cisco | Data Center Network Manager | All | All | All | All |
Application | Cisco | Data Center Network Manager | All | All | All | All |
- cpe:2.3:a:cisco:data_center_network_manager:*:*:*:*:*:*:*:*:
- cpe:2.3:a:cisco:data_center_network_manager:*:*:*:*:*:*:*:*:
No vendor comments have been submitted for this CVE