First published: Wed Jan 20 2021(Updated: )
Multiple vulnerabilities in the web-based management interface of Cisco Data Center Network Manager (DCNM) could allow a remote attacker with network-operator privileges to conduct a cross-site scripting (XSS) attack or a reflected file download (RFD) attack against a user of the interface. For more information about these vulnerabilities, see the Details section of this advisory.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco Data Center Network Manager | <11.5\(1\) |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerabilities in Cisco DCNM are cross-site scripting (XSS) and reflected file download (RFD) attacks.
A remote attacker with network-operator privileges can exploit the vulnerabilities.
The severity of CVE-2021-1250 is medium, with a CVSS score of 5.4.
A remote attacker with network-operator privileges can exploit CVE-2021-1250 by conducting a cross-site scripting (XSS) attack or a reflected file download (RFD) attack against a user of the Cisco DCNM interface.
Yes, Cisco has released a security advisory with fixes and mitigations for CVE-2021-1250. Please refer to the Cisco Security Advisory for more information.