VYPR
Medium severity4.3NVD Advisory· Published Aug 4, 2021· Updated Jun 17, 2026

CVE-2021-1522

CVE-2021-1522

Description

A vulnerability in the change password API of Cisco Connected Mobile Experiences (CMX) could allow an authenticated, remote attacker to alter their own password to a value that does not comply with the strong authentication requirements that are configured on an affected device. This vulnerability exists because a password policy check is incomplete at the time a password is changed at server side using the API. An attacker could exploit this vulnerability by sending a specially crafted API request to the affected device. A successful exploit could allow the attacker to change their own password to a value that does not comply with the configured strong authentication requirements.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

6
  • cpe:2.3:a:cisco:connected_mobile_experiences:10.6.0:*:*:*:*:*:*:*+ 5 more
    • cpe:2.3:a:cisco:connected_mobile_experiences:10.6.0:*:*:*:*:*:*:*
    • cpe:2.3:a:cisco:connected_mobile_experiences:10.6.1:*:*:*:*:*:*:*
    • cpe:2.3:a:cisco:connected_mobile_experiences:10.6.2:*:*:*:*:*:*:*
    • cpe:2.3:a:cisco:connected_mobile_experiences:10.6.3:*:*:*:*:*:*:*
    • (no CPE)
    • (no CPE)range: n/a

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.