A vulnerability in Cisco Connected Mobile Experiences (CMX) could allow a remote, authenticated attacker without administrative privileges to alter the password of any user on an affected system. The vulnerability is due to incorrect handling of authorization checks for changing a password. An authenticated attacker without administrative privileges could exploit this vulnerability by sending a modified HTTP request to an affected device. A successful exploit could allow the attacker to alter the passwords of any user on the system, including an administrative user, and then impersonate that user.
References
Link | Resource |
---|---|
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cmxpe-75Asy9k | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
Information
Published : 2021-01-13 14:15
Updated : 2021-01-20 09:35
NVD link : CVE-2021-1144
Mitre link : CVE-2021-1144
JSON object : View
CWE
CWE-863
Incorrect Authorization
Products Affected
cisco
- connected_mobile_experiences