← Back

CVE-2021-1484

nvd nist
Published: Nov 15, 2024Modified: Aug 4, 2025

JSON object

Loading...
6.5
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Exploitability: 2.8 / Impact: 3.6
Source: psirt@cisco.com (Secondary)

Description

A vulnerability in the web UI of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to inject arbitrary commands on an affected system and cause a denial of service (DoS) condition. This vulnerability is due to improper input validation of user-supplied input to the device template configuration. An attacker could exploit this vulnerability by submitting crafted input to the device template configuration. A successful exploit could allow the attacker to cause a DoS condition on the affected system.Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.

Affected (58)

1 product
Catalyst Sd Wan Manager
Configuration A
58 vulnerable
Vulnerable SoftwareAffected Versions
Cisco
Version 17.2.10
Version 17.2.4
Version 17.2.5
Version 17.2.6
Version 17.2.7
Version 17.2.8
Version 17.2.9
Version 18.2.0
Version 18.3.0
Version 18.3.1.1
Version 18.3.1
Version 18.3.3.1
Version 18.3.3
Version 18.3.4
Version 18.3.5
Version 18.3.6.1
Version 18.3.6
Version 18.3.7
Version 18.3.8
Version 18.4.0.1
Version 18.4.0
Version 18.4.1
Version 18.4.302
Version 18.4.303
Version 18.4.3
Version 18.4.4
Version 18.4.501_es
Version 18.4.5
Version 19.0.0
Version 19.0.1a
Version 19.1.0
Version 19.2.097
Version 19.2.098
Version 19.2.099
Version 19.2.0
Version 19.2.1
Version 19.2.2
Version 19.2.31
Version 19.2.3
Version 19.2.4.0.1
Version 19.2.4
Version 19.2.929
Version 19.3.0
Version 20.1.1.1
Version 20.1.12
Version 20.1.1
Version 20.1.2
Version 20.3.1
Version 20.3.2.1
Version 20.3.2.1_927
Version 20.3.2.1_930
Version 20.3.2
Version 20.3.2_928
Version 20.3.2_929
Version 20.3.3
Version 20.4.1.0.1
Version 20.4.1.1
Version 20.4.1

Timeline

No history available yet.