5.8
CVSSv2

CVE-2021-1134

Published: 29/06/2021 Updated: 02/07/2021
CVSS v2 Base Score: 5.8 | Impact Score: 4.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 7.4 | Impact Score: 5.2 | Exploitability Score: 2.2
VMScore: 516
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:N

Vulnerability Summary

A vulnerability in the Cisco Identity Services Engine (ISE) integration feature of the Cisco DNA Center Software could allow an unauthenticated, remote malicious user to gain unauthorized access to sensitive data. The vulnerability is due to an incomplete validation of the X.509 certificate used when establishing a connection between DNA Center and an ISE server. An attacker could exploit this vulnerability by supplying a crafted certificate and could then intercept communications between the ISE and DNA Center. A successful exploit could allow the malicious user to view and alter sensitive information that the ISE maintains about clients that are connected to the network.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

cisco dna center

Vendor Advisories

A vulnerability in the Cisco Identity Services Engine (ISE) integration feature of the Cisco DNA Center Software could allow an unauthenticated, remote attacker to gain unauthorized access to sensitive data The vulnerability is due to an incomplete validation of the X509 certificate used when establishing a connection between DNA Center and an IS ...