CVE-2021-1271: Cisco Web Security Appliance Stored Cross-Site Scripting Vulnerability
A vulnerability in the web-based management interface of Cisco AsyncOS for Cisco Web Security Appliance (WSA) could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface of an affected device. The vulnerability exists because the web-based management interface does not properly validate user-supplied input. An attacker could exploit this vulnerability by inserting malicious data into a specific data field in an affected interface. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-1271?
CVE-2021-1271 is classified as a moderate severity vulnerability.
How do I fix CVE-2021-1271?
To fix CVE-2021-1271, upgrade to Cisco Web Security Appliance version 12.5.1 or later.
Who is affected by CVE-2021-1271?
CVE-2021-1271 affects users of the web-based management interface of Cisco AsyncOS for Cisco Web Security Appliances up to version 12.5.1.
What type of attack can CVE-2021-1271 enable?
CVE-2021-1271 can enable an authenticated remote attacker to perform a stored cross-site scripting (XSS) attack.
Is authentication required to exploit CVE-2021-1271?
Yes, successful exploitation of CVE-2021-1271 requires the attacker to be authenticated.