CVE-2021-1515
A vulnerability in Cisco SD-WAN vManage Software could allow an unauthenticated, adjacent attacker to gain access to sensitive information. This vulnerability is due to improper access controls on API endpoints when Cisco SD-WAN vManage Software is running in multi-tenant mode. An attacker with access to a device that is managed in the multi-tenant environment could exploit this vulnerability by sending a request to an affected API endpoint on the vManage system. A successful exploit could allow the attacker to gain access to sensitive information that may include hashed credentials that could be used in future attacks.
EPSS 0.37% · 28.5th percentile
Risk Scores
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| cisco | sd-wan_vmanage | 0 |
| Cisco | Cisco SD-WAN vManage | n/a |
Timeline
- May 6, 2021 CVE Published
- May 7, 2021 EPSS Score
- Jul 10, 2021 EPSS Score
- Sep 11, 2021 EPSS Score
- Nov 12, 2021 EPSS Score
- Jan 6, 2022 EPSS Score
- Mar 17, 2022 EPSS Score
- Apr 1, 2022 EPSS Score
- May 18, 2022 EPSS Score
- Jul 21, 2022 EPSS Score
- Sep 21, 2022 EPSS Score
- Nov 23, 2022 EPSS Score