CVE-2021-34707
Last modified
CVE-2021-34707 is a medium-severity vulnerability rated 6.5/10 on the CVSS scale. A vulnerability in the REST API of Cisco Evolved Programmable Network Manager (EPNM) could allow an authenticated, remote attacker to access sensitive data on an affected system. This vulnerability exists because the application does not sufficiently protect sensitive data when responding to an API request. EPSS estimates a 1.09% chance of exploitation in the next 30 days.
Description
A vulnerability in the REST API of Cisco Evolved Programmable Network Manager (EPNM) could allow an authenticated, remote attacker to access sensitive data on an affected system. This vulnerability exists because the application does not sufficiently protect sensitive data when responding to an API request. An attacker could exploit the vulnerability by sending a specific API request to the affected application. A successful exploit could allow the attacker to obtain sensitive information about the application.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Cisco | Evolved Programmable Network Manager | <= 5.0 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2021-34707?
How severe is CVE-2021-34707?
How do I fix CVE-2021-34707?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2021
- CVE-2021-34701A vulnerability in the web-based management interface of Cis…4.3
- CVE-2021-34702A vulnerability in the web-based management interface of Cis…4.3
- CVE-2021-34703A vulnerability in the Link Layer Discovery Protocol (LLDP) …6.5
- CVE-2021-34704A vulnerability in the web services interface of Cisco Adapt…7.5
- CVE-2021-34705A vulnerability in the Voice Telephony Service Provider (VTS…5.3
- CVE-2021-34706A vulnerability in the web-based management interface of Cis…5.4
- CVE-2021-34708Multiple vulnerabilities in image verification checks of Cis…6.7
- CVE-2021-34709Multiple vulnerabilities in image verification checks of Cis…6.4
- CVE-2021-3471Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2021-34710Multiple vulnerabilities in the Cisco ATA 190 Series Analog …8.8
- CVE-2021-34711A vulnerability in the debug shell of Cisco IP Phone softwar…5.5
- CVE-2021-34712A vulnerability in the web-based management interface of Cis…6.5
Are you affected by CVE-2021-34707?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
