First published: Wed Jan 20 2021(Updated: )
Multiple vulnerabilities in certain REST API endpoints of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote attacker to execute arbitrary SQL commands on an affected device. For more information about these vulnerabilities, see the Details section of this advisory.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco Data Center Network Manager | <11.5\(1\) |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-1248 is a vulnerability in certain REST API endpoints of Cisco Data Center Network Manager (DCNM) that could allow an authenticated, remote attacker to execute arbitrary SQL commands on an affected device.
The severity of CVE-2021-1248 is high with a CVSS score of 7.2.
CVE-2021-1248 affects Cisco Data Center Network Manager by causing multiple vulnerabilities in certain REST API endpoints.
To fix CVE-2021-1248, it is recommended to upgrade to Cisco Data Center Network Manager version 11.5(1) or later.
More information about CVE-2021-1248 can be found in the Cisco Security Advisory at the following link: [https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-dcnm-sql-inj-OAQOObP](https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-dcnm-sql-inj-OAQOObP)