First published: Wed Jan 13 2021(Updated: )
A vulnerability in Cisco Connected Mobile Experiences (CMX) could allow a remote, authenticated attacker without administrative privileges to alter the password of any user on an affected system. The vulnerability is due to incorrect handling of authorization checks for changing a password. An authenticated attacker without administrative privileges could exploit this vulnerability by sending a modified HTTP request to an affected device. A successful exploit could allow the attacker to alter the passwords of any user on the system, including an administrative user, and then impersonate that user.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco Connected Mobile Experiences | =10.6.0 | |
Cisco Connected Mobile Experiences | =10.6.1 | |
Cisco Connected Mobile Experiences | =10.6.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-1144 is a vulnerability in Cisco Connected Mobile Experiences (CMX) that allows a remote authenticated attacker to alter the password of any user on the system.
The severity of CVE-2021-1144 is high, with a CVSS score of 8.8.
CVE-2021-1144 affects Cisco Connected Mobile Experiences versions 10.6.0, 10.6.1, and 10.6.2.
An attacker can exploit CVE-2021-1144 by remotely accessing the system and changing the password of any user without administrative privileges.
Yes, Cisco has released a security advisory with mitigation measures for CVE-2021-1144. It is recommended to apply the necessary patches or updates provided by Cisco.