CVE-2021-1474: Cisco Umbrella Link and CSV Formula Injection Vulnerabilities
Multiple vulnerabilities in the Admin audit log export feature and Scheduled Reports feature of Cisco Umbrella could allow an authenticated, remote attacker to perform formula and link injection attacks on an affected device. For more information about these vulnerabilities, see the Details section of this advisory.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-1474?
CVE-2021-1474 has a moderate severity rating due to its potential for formula and link injection attacks.
How do I fix CVE-2021-1474?
To fix CVE-2021-1474, ensure that your Cisco Umbrella instance is updated to the latest patched version provided by Cisco.
Who is affected by CVE-2021-1474?
CVE-2021-1474 affects authenticated users of Cisco Umbrella's Admin audit log export feature and Scheduled Reports feature.
What types of attacks can CVE-2021-1474 enable?
CVE-2021-1474 can enable formula and link injection attacks on affected devices.
Is CVE-2021-1474 actively exploited in the wild?
As of now, there is no public indication that CVE-2021-1474 is actively being exploited in the wild, but it is advisable to apply security updates.