Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%
Get alerts for future matching vulnerabilitiesLog in to subscribe
I. Basic Information for CVE-2021-34766
Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Cisco Smart Software Manager Privilege Escalation Vulnerability
Source: NVD (National Vulnerability Database)
Vulnerability Description
A vulnerability in the web UI of Cisco Smart Software Manager On-Prem (SSM On-Prem) could allow an authenticated, remote attacker to elevate privileges and create, read, update, or delete records and settings in multiple functions. This vulnerability is due to insufficient authorization of the System User and System Operator role capabilities. An attacker could exploit this vulnerability by directly accessing a web resource. A successful exploit could allow the attacker to create, read, update, or delete records and settings in multiple functions without the necessary permissions on the web UI.
Source: NVD (National Vulnerability Database)
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
Source: NVD (National Vulnerability Database)
Vulnerability Type
特权管理不恰当
Source: NVD (National Vulnerability Database)
Vulnerability Title
Cisco Smart Software Manager 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Cisco Smart Software Manager是美国思科(Cisco)公司的一个为用于提供许可证智能管理功能的软件。该软件消除了繁琐的产品激活密钥(PAK)和许可证文件管理,使许可证节点不再锁定到设备,可以支持再任何兼容的设备上使用许可证。 Cisco Smart Software Manager(SSM On Prem)的web UI中存在安全漏洞,该漏洞源于系统用户和系统操作员角色功能的授权不足。攻击者可利用该漏洞提升权限,并在多个功能中创建、读取、更新或删除记录和设置。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)
Affected Products
VendorProductAffected VersionsCPESubscribe
CiscoCisco Smart Software Manager On-Prem n/a -
II. Public POCs for CVE-2021-34766
#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC
III. Intelligence Information for CVE-2021-34766
Please Login to view more intelligence information
IV. Related Vulnerabilities
V. Comments for CVE-2021-34766

No comments yet


Leave a comment