CVE-2021-1483: Cisco SD-WAN vManage Software XML External Entity Vulnerability
A vulnerability in the web UI of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to gain read and write access to information that is stored on an affected system. This vulnerability is due to improper handling of XML External Entity (XXE) entries when the affected software parses certain XML files. An attacker could exploit this vulnerability by persuading a user to import a crafted XML file with malicious entries. A successful exploit could allow the attacker to read and write files within the affected application.Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-1483?
CVE-2021-1483 has been rated as high severity due to its potential to allow authenticated remote attackers to access sensitive information.
How do I fix CVE-2021-1483?
To remediate CVE-2021-1483, update the Cisco SD-WAN vManage Software to the latest version that addresses this vulnerability.
What types of systems are affected by CVE-2021-1483?
CVE-2021-1483 affects the Cisco SD-WAN vManage Software, allowing vulnerabilities to compromise its web UI.
Can CVE-2021-1483 be exploited remotely?
Yes, CVE-2021-1483 can be exploited by an authenticated remote attacker due to improper handling of XML External Entity entries.
What is the impact of CVE-2021-1483?
The impact of CVE-2021-1483 includes the potential for unauthorized read and write access to sensitive information on affected systems.