← Back to CVE List

CVE-2021-1143

Published: 2021-01-13T22:15Z
Last Modified: 2024-11-21T05:43Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
A vulnerability in Cisco Connected Mobile Experiences (CMX) API authorizations could allow an authenticated, remote attacker to enumerate what users exist on the system. The vulnerability is due to a lack of authorization checks for certain API GET requests. An attacker could exploit this vulnerability by sending specific API GET requests to an affected device. A successful exploit could allow the attacker to enumerate users of the CMX system. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt