VDB

CVE-2021-1486

CVE-2021-1486 PUBLISHED CVSS 5.300000190734863 MEDIUM

A vulnerability in Cisco SD-WAN vManage Software could allow an unauthenticated, remote attacker to enumerate user accounts. This vulnerability is due to the improper handling of HTTP headers. An attacker could exploit this vulnerability by sending authenticated requests to an affected system. A successful exploit could allow the attacker to compare the HTTP responses that are returned by the affected system to determine which accounts are valid user accounts.

EPSS 1.22% · 67.7th percentile

Risk Scores

CVSS 3.1
5.300000190734863
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
EPSS Score
1.22%
67.7th percentile

Affected Products

VendorProductVersions
CiscoCisco SD-WAN vManagen/a
ciscocatalyst_sd-wan_manager20.4
ciscosd-wan_vmanage0

Timeline

  • May 6, 2021 CVE Published
  • May 7, 2021 EPSS Score
  • Jul 11, 2021 EPSS Score
  • Sep 11, 2021 EPSS Score
  • Jan 6, 2022 EPSS Score
  • Jan 14, 2022 EPSS Score
  • Feb 4, 2022 EPSS Score
  • Mar 18, 2022 EPSS Score
  • Apr 1, 2022 EPSS Score
  • May 19, 2022 EPSS Score
  • Sep 22, 2022 EPSS Score
  • Nov 24, 2022 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›