A vulnerability in the web-based management interface of Cisco Tetration could allow an authenticated, remote attacker to perform a stored cross-site scripting (XSS) attack on an affected system. This vulnerability exists because the web-based management interface does not sufficiently validate user-supplied input. An attacker could exploit this vulnerability by injecting malicious code into specific pages of the interface. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information. To exploit this vulnerability, the attacker would need valid administrative credentials.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Thu, 07 Nov 2024 22:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: cisco

Published:

Updated: 2024-11-07T21:47:00.584Z

Reserved: 2021-06-15T00:00:00

Link: CVE-2021-34789

cve-icon Vulnrichment

Updated: 2024-08-04T00:19:48.151Z

cve-icon NVD

Status : Modified

Published: 2021-10-21T03:15:07.083

Modified: 2024-11-21T06:11:12.430

Link: CVE-2021-34789

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.