VDB

CVE-2021-34707

CVE-2021-34707 PUBLISHED CVSS 6.5 MEDIUM

A vulnerability in the REST API of Cisco Evolved Programmable Network Manager (EPNM) could allow an authenticated, remote attacker to access sensitive data on an affected system. This vulnerability exists because the application does not sufficiently protect sensitive data when responding to an API request. An attacker could exploit the vulnerability by sending a specific API request to the affected application. A successful exploit could allow the attacker to obtain sensitive information about the application.

EPSS 1.10% · 63.3th percentile

Risk Scores

CVSS 3.1
6.5
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
EPSS Score
1.10%
63.3th percentile

Affected Products

VendorProductVersions
CiscoCisco Evolved Programmable Network Manager (EPNM)*
ciscoevolved_programmable_network_manager0

Timeline

  • Aug 4, 2021 CVE Published
  • Aug 5, 2021 EPSS Score
  • Oct 3, 2021 EPSS Score
  • Dec 1, 2021 EPSS Score
  • Jan 29, 2022 EPSS Score
  • Feb 4, 2022 EPSS Score
  • Mar 29, 2022 EPSS Score
  • Apr 1, 2022 EPSS Score
  • May 28, 2022 EPSS Score
  • Jul 27, 2022 EPSS Score
  • Nov 22, 2022 EPSS Score
  • Jan 20, 2023 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›