First published: Wed Jan 13 2021(Updated: )
A vulnerability in Cisco Connected Mobile Experiences (CMX) API authorizations could allow an authenticated, remote attacker to enumerate what users exist on the system. The vulnerability is due to a lack of authorization checks for certain API GET requests. An attacker could exploit this vulnerability by sending specific API GET requests to an affected device. A successful exploit could allow the attacker to enumerate users of the CMX system.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco Connected Mobile Experiences | =10.6.0 | |
Cisco Connected Mobile Experiences | =10.6.1 | |
Cisco Connected Mobile Experiences | =10.6.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this vulnerability is CVE-2021-1143.
The severity of CVE-2021-1143 is medium with a severity value of 4.3.
CVE-2021-1143 affects Cisco Connected Mobile Experiences (CMX) versions 10.6.0, 10.6.1, and 10.6.2.
The impact of CVE-2021-1143 is that an authenticated, remote attacker could enumerate users on the system.
Yes, Cisco has released a fix for CVE-2021-1143. Please refer to the Cisco Security Advisory for more information.