ID

VAR-202101-1048


CVE

CVE-2021-1265


TITLE

Cisco DNA Center  Vulnerability of important information in plaintext

Trust: 0.8

sources: JVNDB: JVNDB-2021-002605

DESCRIPTION

A vulnerability in the configuration archive functionality of Cisco DNA Center could allow any privilege-level authenticated, remote attacker to obtain the full unmasked running configuration of managed devices. The vulnerability is due to the configuration archives files being stored in clear text, which can be retrieved by various API calls. An attacker could exploit this vulnerability by authenticating to the device and executing a series of API calls. A successful exploit could allow the attacker to retrieve the full unmasked running configurations of managed devices. Cisco DNA Center Contains a vulnerability in the plaintext storage of important information.Information may be obtained. Cisco DNA Center is a network management and command center service of Cisco (Cisco)

Trust: 1.8

sources: NVD: CVE-2021-1265 // JVNDB: JVNDB-2021-002605 // VULHUB: VHN-374319 // VULMON: CVE-2021-1265

AFFECTED PRODUCTS

vendor:ciscomodel:dna centerscope:ltversion:2.1.1.0

Trust: 1.0

vendor:シスコシステムズmodel:cisco dna centerscope:eqversion: -

Trust: 0.8

sources: JVNDB: JVNDB-2021-002605 // NVD: CVE-2021-1265

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2021-1265
value: MEDIUM

Trust: 1.0

ykramarz@cisco.com: CVE-2021-1265
value: HIGH

Trust: 1.0

NVD: CVE-2021-1265
value: MEDIUM

Trust: 0.8

CNNVD: CNNVD-202101-1553
value: MEDIUM

Trust: 0.6

VULHUB: VHN-374319
value: MEDIUM

Trust: 0.1

VULMON: CVE-2021-1265
value: MEDIUM

Trust: 0.1

nvd@nist.gov: CVE-2021-1265
severity: MEDIUM
baseScore: 4.0
vectorString: AV:N/AC:L/AU:S/C:P/I:N/A:N
accessVector: NETWORK
accessComplexity: LOW
authentication: SINGLE
confidentialityImpact: PARTIAL
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 8.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.9

VULHUB: VHN-374319
severity: MEDIUM
baseScore: 4.0
vectorString: AV:N/AC:L/AU:S/C:P/I:N/A:N
accessVector: NETWORK
accessComplexity: LOW
authentication: SINGLE
confidentialityImpact: PARTIAL
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 8.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

nvd@nist.gov: CVE-2021-1265
baseSeverity: MEDIUM
baseScore: 6.5
vectorString: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: LOW
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 2.8
impactScore: 3.6
version: 3.1

Trust: 1.0

ykramarz@cisco.com: CVE-2021-1265
baseSeverity: HIGH
baseScore: 7.7
vectorString: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: LOW
userInteraction: NONE
scope: CHANGED
confidentialityImpact: HIGH
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 3.1
impactScore: 4.0
version: 3.0

Trust: 1.0

NVD: CVE-2021-1265
baseSeverity: MEDIUM
baseScore: 6.5
vectorString: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: LOW
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: NONE
impactScore: NONE
version: 3.0

Trust: 0.8

sources: VULHUB: VHN-374319 // VULMON: CVE-2021-1265 // JVNDB: JVNDB-2021-002605 // CNNVD: CNNVD-202101-1553 // NVD: CVE-2021-1265 // NVD: CVE-2021-1265

PROBLEMTYPE DATA

problemtype:CWE-312

Trust: 1.1

problemtype:Plaintext storage of important information (CWE-312) [ Other ]

Trust: 0.8

sources: VULHUB: VHN-374319 // JVNDB: JVNDB-2021-002605 // NVD: CVE-2021-1265

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-202101-1553

TYPE

other

Trust: 0.6

sources: CNNVD: CNNVD-202101-1553

PATCH

title:cisco-sa-dnacid-OfeeRjcnurl:https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-dnacid-OfeeRjcn

Trust: 0.8

title:Cisco DNA Center Security vulnerabilitiesurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=139811

Trust: 0.6

title:Cisco: Cisco DNA Center Information Disclosure Vulnerabilityurl:https://vulmon.com/vendoradvisory?qidtp=cisco_security_advisories_and_alerts_ciscoproducts&qid=cisco-sa-dnacid-OfeeRjcn

Trust: 0.1

sources: VULMON: CVE-2021-1265 // JVNDB: JVNDB-2021-002605 // CNNVD: CNNVD-202101-1553

EXTERNAL IDS

db:NVDid:CVE-2021-1265

Trust: 2.6

db:JVNDBid:JVNDB-2021-002605

Trust: 0.8

db:AUSCERTid:ESB-2021.0243

Trust: 0.6

db:CNNVDid:CNNVD-202101-1553

Trust: 0.6

db:VULHUBid:VHN-374319

Trust: 0.1

db:VULMONid:CVE-2021-1265

Trust: 0.1

sources: VULHUB: VHN-374319 // VULMON: CVE-2021-1265 // JVNDB: JVNDB-2021-002605 // CNNVD: CNNVD-202101-1553 // NVD: CVE-2021-1265

REFERENCES

url:https://tools.cisco.com/security/center/content/ciscosecurityadvisory/cisco-sa-dnacid-ofeerjcn

Trust: 2.5

url:https://nvd.nist.gov/vuln/detail/cve-2021-1265

Trust: 1.4

url:https://www.auscert.org.au/bulletins/esb-2021.0243/

Trust: 0.6

url:https://cwe.mitre.org/data/definitions/312.html

Trust: 0.1

url:https://nvd.nist.gov

Trust: 0.1

sources: VULHUB: VHN-374319 // VULMON: CVE-2021-1265 // JVNDB: JVNDB-2021-002605 // CNNVD: CNNVD-202101-1553 // NVD: CVE-2021-1265

SOURCES

db:VULHUBid:VHN-374319
db:VULMONid:CVE-2021-1265
db:JVNDBid:JVNDB-2021-002605
db:CNNVDid:CNNVD-202101-1553
db:NVDid:CVE-2021-1265

LAST UPDATE DATE

2024-08-14T13:04:23.137000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-374319date:2021-01-27T00:00:00
db:VULMONid:CVE-2021-1265date:2021-01-27T00:00:00
db:JVNDBid:JVNDB-2021-002605date:2021-09-27T09:05:00
db:CNNVDid:CNNVD-202101-1553date:2021-02-01T00:00:00
db:NVDid:CVE-2021-1265date:2021-01-27T16:50:57.907

SOURCES RELEASE DATE

db:VULHUBid:VHN-374319date:2021-01-20T00:00:00
db:VULMONid:CVE-2021-1265date:2021-01-20T00:00:00
db:JVNDBid:JVNDB-2021-002605date:2021-09-27T00:00:00
db:CNNVDid:CNNVD-202101-1553date:2021-01-20T00:00:00
db:NVDid:CVE-2021-1265date:2021-01-20T20:15:15.407