VDB
CVE-2021-1486
CVE-2021-1486
PUBLISHED
CVSS 5.300000190734863 MEDIUM
A vulnerability in Cisco SD-WAN vManage Software could allow an unauthenticated, remote attacker to enumerate user accounts. This vulnerability is due to the improper handling of HTTP headers. An attacker could exploit this vulnerability by sending authenticated requests to an affected system. A successful exploit could allow the attacker to compare the HTTP responses that are returned by the affected system to determine which accounts are valid user accounts.
EPSS 1.22% · 67.7th percentile
Risk Scores
CVSS 3.1
5.300000190734863
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
EPSS Score
1.22%
67.7th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Cisco | Cisco SD-WAN vManage | n/a |
| cisco | catalyst_sd-wan_manager | 20.4 |
| cisco | sd-wan_vmanage | 0 |
Timeline
- May 6, 2021 CVE Published
- May 7, 2021 EPSS Score
- Jul 11, 2021 EPSS Score
- Sep 11, 2021 EPSS Score
- Jan 6, 2022 EPSS Score
- Jan 14, 2022 EPSS Score
- Feb 4, 2022 EPSS Score
- Mar 18, 2022 EPSS Score
- Apr 1, 2022 EPSS Score
- May 19, 2022 EPSS Score
- Sep 22, 2022 EPSS Score
- Nov 24, 2022 EPSS Score