A vulnerability in the web UI of Cisco Smart Software Manager On-Prem (SSM On-Prem) could allow an authenticated, remote attacker to elevate privileges and create, read, update, or delete records and settings in multiple functions. This vulnerability is due to insufficient authorization of the System User and System Operator role capabilities. An attacker could exploit this vulnerability by directly accessing a web resource. A successful exploit could allow the attacker to create, read, update, or delete records and settings in multiple functions without the necessary permissions on the web UI.
Metrics
Affected Vendors & Products
References
History
Thu, 07 Nov 2024 22:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
MITRE
Status: PUBLISHED
Assigner: cisco
Published: 2021-10-06T19:45:53.961782Z
Updated: 2024-11-07T21:49:16.890Z
Reserved: 2021-06-15T00:00:00
Link: CVE-2021-34766
Vulnrichment
Updated: 2024-08-04T00:19:48.203Z
NVD
Status : Modified
Published: 2021-10-06T20:15:13.287
Modified: 2024-11-21T06:11:09.140
Link: CVE-2021-34766
Redhat
No data.