CVE-2021-34766 is a high-severity vulnerability affecting Cisco Smart Software Manager On-Prem, allowing an authenticated, remote attacker to escalate privileges. This flaw stems from insufficient authorization within the System User and System Operator roles, enabling unauthorized creation, reading, updating, or deletion of records and settings across various functions. With a CVSS score of 8.8, exploitation is straightforward, requiring only authenticated access to a web resource, and can lead to full compromise of data integrity and availability. There is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 8-202108CPE matchmatch criteria | cpe:2.3:a:cisco:smart_software_manager_on-prem:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.