VDB

CVE-2021-34782

CVE-2021-34782 PUBLISHED CVSS 4.300000190734863 MEDIUM

A vulnerability in the API endpoints for Cisco DNA Center could allow an authenticated, remote attacker to gain access to sensitive information that should be restricted. The attacker must have valid device credentials. This vulnerability is due to improper access controls on API endpoints. An attacker could exploit the vulnerability by sending a specific API request to an affected application. A successful exploit could allow the attacker to obtain sensitive information about other users who are configured with higher privileges on the application.

EPSS 0.78% · 52.9th percentile

Risk Scores

CVSS 3.1
4.300000190734863
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
EPSS Score
0.78%
52.9th percentile

Affected Products

VendorProductVersions
ciscocatalyst_center0, 2.2.3.0
CiscoCisco Digital Network Architecture Center (DNA Center)n/a

Timeline

  • Oct 6, 2021 CVE Published
  • Oct 7, 2021 EPSS Score
  • Dec 3, 2021 EPSS Score
  • Jan 6, 2022 EPSS Score
  • Feb 4, 2022 EPSS Score
  • Mar 27, 2022 EPSS Score
  • Apr 1, 2022 EPSS Score
  • May 22, 2022 EPSS Score
  • Jul 19, 2022 EPSS Score
  • Sep 14, 2022 EPSS Score
  • Jan 6, 2023 EPSS Score
  • Mar 4, 2023 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›