First published: Wed Jan 20 2021(Updated: )
Multiple vulnerabilities in the web-based management interface of Cisco Data Center Network Manager (DCNM) could allow a remote attacker with network-operator privileges to conduct a cross-site scripting (XSS) attack or a reflected file download (RFD) attack against a user of the interface. For more information about these vulnerabilities, see the Details section of this advisory.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco Data Center Network Manager | <11.5\(1\) |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-1253 is a vulnerability in the web-based management interface of Cisco Data Center Network Manager (DCNM) that could allow an attacker to conduct a cross-site scripting (XSS) attack or a reflected file download (RFD) attack.
CVE-2021-1253 has a severity score of 5.4 out of 10, making it a medium severity vulnerability.
CVE-2021-1253 affects Cisco Data Center Network Manager (DCNM) versions up to and including 11.5(1).
Cross-site scripting (XSS) is a type of web security vulnerability where an attacker injects malicious scripts into a trusted website, which then executes the script in the user's browser.
A reflected file download (RFD) attack is a type of web-based attack where an attacker tricks the user into downloading a file from a trusted source that is actually controlled by the attacker.