CVE-2021-1425

MEDIUM EPSS 40.4%
Published Nov 18, 20241y ago · Modified Jun 17, 20261w ago
6.5 CVSS 3.1
Medium
Find Similar
Published Nov 18, 2024 1y ago
Last Modified Jun 17, 2026 1w ago

Description

A vulnerability in the web-based management interface of Cisco AsyncOS Software for Cisco Content Security Management Appliance (SMA) could allow an authenticated, remote attacker to access sensitive information on an affected device. The vulnerability exists because confidential information is being included in HTTP requests that are exchanged between the user and the device. An attacker could exploit this vulnerability by looking at the raw HTTP requests that are sent to the interface. A successful exploit could allow the attacker to obtain some of the passwords that are configured throughout the interface.Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.

CVSS Details

Base Score
6.5
Exploitability
2.8
Impact
3.6
Vector string
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Attack Vector Network
Attack Complexity Low
Privileges Required Low
User Interaction None
Scope Unchanged
Confidentiality High
Integrity None
Availability None

Threat Intelligence

EPSS Exploit Probability
40.4% percentile
Exploit & Patch Status
No Known Exploit
No Patch Available

Weaknesses 1

CWE-201

Affected Products 10

VendorProductVersionRange
ciscoasyncos* <13.8.0
ciscocontent_security_management_appliance_smav_m000v*any
ciscocontent_security_management_appliance_smav_m100v*any
ciscocontent_security_management_appliance_smav_m300v*any
ciscocontent_security_management_appliance_smav_m600v*any
ciscocontent_security_management_appliance_sma_m190*any
ciscocontent_security_management_appliance_sma_m195*any
ciscocontent_security_management_appliance_sma_m395*any
ciscocontent_security_management_appliance_sma_m690*any
ciscocontent_security_management_appliance_sma_m695*any

References 1

  • sec.cloudapps.cisco.com https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-esa-sma-info-disclo-VOu2GHbZ
    Vendor Advisory

Remediation

No remediation data recorded yet

Check vendor advisories and the NVD entry for patch availability.