VDB

CVE-2021-34782

CVE-2021-34782 PUBLISHED CVSS 4.300000190734863 MEDIUM

A vulnerability in the API endpoints for Cisco DNA Center could allow an authenticated, remote attacker to gain access to sensitive information that should be restricted. The attacker must have valid device credentials. This vulnerability is due to improper access controls on API endpoints. An attacker could exploit the vulnerability by sending a specific API request to an affected application. A successful exploit could allow the attacker to obtain sensitive information about other users who are configured with higher privileges on the application.

EPSS 0.28% · 51.5th percentile

Risk Scores

CVSS 3.1
4.300000190734863
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
EPSS Score
0.28%
51.5th percentile

Affected Products

VendorProductVersions
ciscocatalyst_center0, 2.2.3.0
CiscoCisco Digital Network Architecture Center (DNA Center)n/a

Timeline

  • Oct 6, 2021 CVE Published
  • Oct 7, 2021 EPSS Score
  • Dec 3, 2021 EPSS Score
  • Jan 6, 2022 EPSS Score
  • Jan 28, 2022 EPSS Score
  • Mar 26, 2022 EPSS Score
  • Apr 1, 2022 EPSS Score
  • May 22, 2022 EPSS Score
  • Jul 19, 2022 EPSS Score
  • Sep 13, 2022 EPSS Score
  • Nov 9, 2022 EPSS Score
  • Jan 5, 2023 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›