CVE-2021-34707
Last modified
CVE-2021-34707 is a medium-severity vulnerability rated 6.5/10 on the CVSS scale. A vulnerability in the REST API of Cisco Evolved Programmable Network Manager (EPNM) could allow an authenticated, remote attacker to access sensitive data on an affected system. This vulnerability exists because the application does not sufficiently protect sensitive data when responding to an API request. EPSS estimates a 1.09% chance of exploitation in the next 30 days.
Description
A vulnerability in the REST API of Cisco Evolved Programmable Network Manager (EPNM) could allow an authenticated, remote attacker to access sensitive data on an affected system. This vulnerability exists because the application does not sufficiently protect sensitive data when responding to an API request. An attacker could exploit the vulnerability by sending a specific API request to the affected application. A successful exploit could allow the attacker to obtain sensitive information about the application.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Cisco | Evolved Programmable Network Manager | <= 5.0 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2021-34707?
How severe is CVE-2021-34707?
How do I fix CVE-2021-34707?
Are you affected by CVE-2021-34707?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
