CVE-2021-1474

Published on: 04/08/2021 12:00:00 AM UTC

Last Modified on: 04/08/2021 11:26:00 AM UTC

CVE-2021-1474 - advisory for cisco-sa-umbrella-inject-gbZGHP5T

Source: Mitre
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L

Certain versions of Umbrella from Cisco contain the following vulnerability:

Multiple vulnerabilities in the Admin audit log export feature and Scheduled Reports feature of Cisco Umbrella could allow an authenticated, remote attacker to perform formula and link injection attacks on an affected device. For more information about these vulnerabilities, see the Details section of this advisory.

  • CVE-2021-1474 has been assigned by [email protected] to track the vulnerability
  • The Cisco Product Security Incident Response Team (PSIRT) is not aware of any public announcements or malicious use of the vulnerabilities that are described in this advisory.
  • Affected Vendor/Software: Cisco - Cisco Umbrella Insights Virtual Appliance version n/a

CVE References

Description Tags Link
Cisco Umbrella Link and CSV Formula Injection Vulnerabilities tools.cisco.com
text/html
URL Logo CISCO 20210407 Cisco Umbrella Link and CSV Formula Injection Vulnerabilities

Known Affected Configurations (CPE V2.3)

Type Vendor Product Version Update Edition Language
ApplicationCiscoUmbrella-AllAllAll
  • cpe:2.3:a:cisco:umbrella:-:*:*:*:*:*:*:*:

Social Mentions

Source Title Posted (UTC)
Twitter Icon @CVEreport CVE-2021-1474 : Multiple vulnerabilities in the Admin audit log export feature and Scheduled Reports feature of Cis… twitter.com/i/web/status/1… 2021-04-08 04:23:07