CVE-2021-1249: Cisco Data Center Network Manager Vulnerabilities
Multiple vulnerabilities in the web-based management interface of Cisco Data Center Network Manager (DCNM) could allow a remote attacker with network-operator privileges to conduct a cross-site scripting (XSS) attack or a reflected file download (RFD) attack against a user of the interface. For more information about these vulnerabilities, see the Details section of this advisory.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-1249?
CVE-2021-1249 is a vulnerability in the web-based management interface of Cisco Data Center Network Manager (DCNM) that allows a remote attacker to conduct a cross-site scripting (XSS) or reflected file download (RFD) attack.
What is the severity of CVE-2021-1249?
The severity of CVE-2021-1249 is medium, with a CVSS score of 5.4.
What software is affected by CVE-2021-1249?
Cisco Data Center Network Manager (DCNM) versions up to 11.5(1) are affected by CVE-2021-1249.
How can a remote attacker exploit CVE-2021-1249?
A remote attacker with network-operator privileges can exploit CVE-2021-1249 by conducting a cross-site scripting (XSS) attack or a reflected file download (RFD) attack against a user of the management interface.
Where can I find more information about CVE-2021-1249?
You can find more information about CVE-2021-1249 in the Cisco Security Advisory at this link: [https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-dcnm-xss-vulns-GuUJ39gh](https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-dcnm-xss-vulns-GuUJ39gh)