CVE-2021-1255: Cisco Data Center Network Manager REST API Vulnerabilities
Multiple vulnerabilities in the REST API endpoint of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote attacker to view, modify, and delete data without proper authorization. For more information about these vulnerabilities, see the Details section of this advisory.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2021-1255.
What is the severity of CVE-2021-1255?
The severity of CVE-2021-1255 is medium, with a CVSS score of 5.4.
What is the affected software?
The affected software is Cisco Data Center Network Manager up to version 11.4(1).
How can an attacker exploit CVE-2021-1255?
An authenticated remote attacker can exploit CVE-2021-1255 to view, modify, and delete data without proper authorization through the Cisco Data Center Network Manager REST API endpoint.
Where can I find more information about CVE-2021-1255?
You can find more information about CVE-2021-1255 in the Cisco Security Advisory at the following link: https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-dcnm-api-path-TpTApx2p