VDB
CVE-2021-34712
CVE-2021-34712
PUBLISHED
CVSS 5.400000095367432 MEDIUM
A vulnerability in the web-based management interface of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to conduct cypher query language injection attacks on an affected system. This vulnerability is due to insufficient input validation by the web-based management interface. An attacker could exploit this vulnerability by sending crafted HTTP requests to the interface of an affected system. A successful exploit could allow the attacker to obtain sensitive information.
EPSS 0.74% · 51.6th percentile
Risk Scores
CVSS 3.1
5.400000095367432
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
EPSS Score
0.74%
51.6th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Cisco | Cisco SD-WAN vManage | n/a |
| cisco | catalyst_sd-wan_manager | 20.4, 20.5, 20.6 |
| cisco | sd-wan_vmanage | 20.3 |
Timeline
- Sep 23, 2021 EPSS Score
- Sep 23, 2021 CVE Published
- Nov 19, 2021 EPSS Score
- Jan 6, 2022 EPSS Score
- Feb 4, 2022 EPSS Score
- Mar 14, 2022 EPSS Score
- Apr 1, 2022 EPSS Score
- May 10, 2022 EPSS Score
- Jul 7, 2022 EPSS Score
- Sep 3, 2022 EPSS Score
- Dec 27, 2022 EPSS Score
- Feb 22, 2023 EPSS Score