{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-04-21T15:47:44.086","vulnerabilities":[{"cve":{"id":"CVE-2021-1589","sourceIdentifier":"psirt@cisco.com","published":"2021-09-23T03:15:11.717","lastModified":"2024-11-21T05:44:41.450","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"A vulnerability in the disaster recovery feature of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to gain unauthorized access to user credentials. This vulnerability exists because access to API endpoints is not properly restricted. An attacker could exploit this vulnerability by sending a request to an API endpoint. A successful exploit could allow the attacker to gain unauthorized access to administrative credentials that could be used in further attacks."},{"lang":"es","value":"Una vulnerabilidad en la funcionalidad disaster recovery de Cisco SD-WAN vManage Software podría permitir a un atacante remoto autenticado conseguir acceso no autorizado a las credenciales del usuario. Esta vulnerabilidad se presenta porque el acceso a los endpoints de la API no está debidamente restringido. Un atacante podría explotar esta vulnerabilidad mediante el envío de una petición a un endpoint de la API. Una explotación con éxito podría permitir al atacante conseguir acceso no autorizado a credenciales administrativas que podrían ser usadas en otros ataques"}],"metrics":{"cvssMetricV31":[{"source":"psirt@cisco.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":3.6},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":3.6}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:S/C:P/I:N/A:N","baseScore":3.5,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"LOW","exploitabilityScore":6.8,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"psirt@cisco.com","type":"Secondary","description":[{"lang":"en","value":"CWE-256"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-522"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:cisco:sd-wan:*:*:*:*:*:*:*:*","versionStartIncluding":"20.3","versionEndExcluding":"20.3.4","matchCriteriaId":"EE777DCB-F32F-4ED5-859E-65C379FCE51F"},{"vulnerable":true,"criteria":"cpe:2.3:a:cisco:sd-wan:*:*:*:*:*:*:*:*","versionStartIncluding":"20.4","versionEndExcluding":"20.4.2","matchCriteriaId":"A93BF4C5-4F64-4A52-B891-FE2984190A9A"},{"vulnerable":true,"criteria":"cpe:2.3:a:cisco:sd-wan:*:*:*:*:*:*:*:*","versionStartIncluding":"20.5","versionEndExcluding":"20.5.2","matchCriteriaId":"73F73343-A8E8-4FC0-8E5D-D7020A0FC040"},{"vulnerable":true,"criteria":"cpe:2.3:a:cisco:sd-wan:*:*:*:*:*:*:*:*","versionStartIncluding":"20.6","versionEndExcluding":"20.6.1","matchCriteriaId":"CF68FBC2-7B33-485D-8BF3-7792A87AF159"}]}]}],"references":[{"url":"https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sd-wan-credentials-ydYfskzZ","source":"psirt@cisco.com","tags":["Patch","Vendor Advisory"]},{"url":"https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sd-wan-credentials-ydYfskzZ","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Vendor Advisory"]}]}}]}