6.5
CVSSv2

CVE-2021-1144

Published: 13/01/2021 Updated: 07/11/2023
CVSS v2 Base Score: 6.5 | Impact Score: 6.4 | Exploitability Score: 8
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 578
Vector: AV:N/AC:L/Au:S/C:P/I:P/A:P

Vulnerability Summary

A vulnerability in Cisco Connected Mobile Experiences (CMX) could allow a remote, authenticated attacker without administrative privileges to alter the password of any user on an affected system. The vulnerability is due to incorrect handling of authorization checks for changing a password. An authenticated attacker without administrative privileges could exploit this vulnerability by sending a modified HTTP request to an affected device. A successful exploit could allow the malicious user to alter the passwords of any user on the system, including an administrative user, and then impersonate that user.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

cisco connected mobile experiences 10.6.2

cisco connected mobile experiences 10.6.0

cisco connected mobile experiences 10.6.1

Vendor Advisories

A vulnerability in Cisco Connected Mobile Experiences (CMX) could allow a remote, authenticated attacker without administrative privileges to alter the password of any user on an affected system The vulnerability is due to incorrect handling of authorization checks for changing a password An authenticated attacker without administrative privilege ...