CVE-2021-1589: Cisco SD-WAN vManage Software Disaster Recovery Feature Password Exposure Vulnerability
A vulnerability in the disaster recovery feature of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to gain unauthorized access to user credentials. This vulnerability exists because access to API endpoints is not properly restricted. An attacker could exploit this vulnerability by sending a request to an API endpoint. A successful exploit could allow the attacker to gain unauthorized access to administrative credentials that could be used in further attacks.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2021-1589?
CVE-2021-1589 is a vulnerability in the disaster recovery feature of Cisco SD-WAN vManage Software that allows an authenticated, remote attacker to gain unauthorized access to user credentials.
How does CVE-2021-1589 impact Cisco SD-WAN vManage Software?
CVE-2021-1589 allows an attacker to exploit the vulnerability in the disaster recovery feature of Cisco SD-WAN vManage Software, resulting in unauthorized access to user credentials.
Is an attacker required to be authenticated to exploit CVE-2021-1589?
Yes, an attacker needs to be authenticated to exploit CVE-2021-1589 and gain unauthorized access to user credentials.
What is the severity of CVE-2021-1589?
CVE-2021-1589 has a severity rating of 6.5 out of 10, indicating a medium-level vulnerability.
How can I fix CVE-2021-1589 in Cisco SD-WAN vManage Software?
To fix CVE-2021-1589, it is recommended to apply the necessary patches or updates provided by Cisco.