LiveActive security incident?Get immediate response
CVE Record

CVE-2021-1479: Cisco SD-WAN vManage Software Vulnerabilities

Multiple vulnerabilities in Cisco SD-WAN vManage Software could allow an unauthenticated, remote attacker to execute arbitrary code or allow an authenticated, local attacker to gain escalated privileges on an affected system. For more information about these vulnerabilities, see the Details section of this advisory.

HighCVSS 7.8Not KEV-listedUpdated
Glexia's TakeAutomated analysishigh

Security readout for executives and security teams

Plain-English summary

CVE-2021-1479 affects Cisco SD-WAN vManage Software. The supplied CVSS vector indicates a low-privileged local attacker could gain full confidentiality, integrity, and availability impact on an affected system. The source bundle does not provide exact affected versions or fixed releases.

Executive priority

Treat this as a high-priority infrastructure remediation item if Cisco vManage is present. Business urgency comes from potential full system compromise after low-privileged local access, but the supplied evidence does not indicate known active exploitation.

Technical view

The CVE is associated with CWE-119 and Cisco SD-WAN vManage Software. CVSS 3.1 is 7.8 with AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H, indicating local authenticated exploitation with high system impact. The broader Cisco advisory also references multiple vManage vulnerabilities.

Likely exposure

Exposure is likely limited to organizations operating Cisco SD-WAN vManage Software. The supplied bundle lists Cisco SD-WAN Solution with versions as n/a, so exact version exposure requires the Cisco advisory or asset validation.

Exploitation context

The source bundle does not show CISA KEV inclusion and provides no evidence of active exploitation. The CVSS vector for this CVE requires local access and low privileges; do not assume unauthenticated remote exploitation for this specific CVE from the supplied data alone.

Researcher notes

Use the Cisco advisory as the authoritative source for version mapping and remediation. The CVSS vector points to local authenticated privilege escalation for CVE-2021-1479, while the advisory title covers multiple vManage vulnerabilities with different impacts.

Mitigation direction

  • Identify all Cisco SD-WAN vManage deployments and ownership.
  • Review Cisco advisory cisco-sa-vmanage-YuTVWqy for affected and fixed releases.
  • Apply Cisco-recommended updates or mitigations where applicable.
  • Restrict local and administrative access to vManage systems.
  • Monitor vManage systems for unauthorized privilege changes.

Validation and detection

  • Confirm deployed vManage versions against Cisco advisory guidance.
  • Verify whether affected systems have received Cisco-recommended fixes.
  • Review access controls for local and privileged vManage users.
  • Check logs for unexpected administrative actions or privilege escalation indicators.
  • Document any systems requiring vendor-supported remediation exceptions.
Prepared
Confidence
medium
Sources
3

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Potential ATT&CK relevance

Conservative CVE-to-ATT&CK context

These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.

ATT&CK lookup starting points

Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.

cwe · low confidence lookup

CWE-119: Exact CWE lookup

Use the exact CWE identifier as the starting point before reviewing related ATT&CK behavior. Open the exact CWE lookup page first, then review the ATT&CK searches from that MITRE weakness context. This is a Glexia lookup hint, not an official ATT&CK mapping.

Open ATT&CK lookup
description · low confidence lookup

Execution behavior lookup

The CVE wording references code or command execution, so execution technique review may help defensive triage. This is a Glexia inferred lookup path, not an official MITRE, ATT&CK, or CVE Program mapping.

Open ATT&CK lookup
cve · low confidence lookup

CVE-2021-1479 mapping review

Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.

Open ATT&CK lookup
Vulnerability profileCVE Program record
Severity
High
CVSS
7.8 (3.1)
Known Exploited
No
Published

Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Official CVE source material

CNA and ADP enrichment extracted from CVE v5

These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.

1CVSS vectors
0Timeline events
0ADP providers
2Source links

CVSS vector scores

1 official score

We collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.

ScoreVersionSeverityVectorExploitImpactSource
7.8CVSS 3.1HighCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H1.85.9Primary CVE score

Vulnerability scoring details

Base CVSS 3.1 score

7.8High
CVSS 3.1 vector shape for CVE-2021-1479Attack VectorAttack ComplexityPrivileges RequiredUser InteractionScopeConfidentiality ImpactIntegrity ImpactAvailability Impact

Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Attack Vector
NetworkAdjacentLocalPhysical
Attack Complexity
LowHigh
Privileges Required
NoneLowHigh
User Interaction
NoneRequired
Scope
ChangedUnchanged
Confidentiality Impact
HighLowNone
Integrity Impact
HighLowNone
Availability Impact
HighLowNone

Source materials

Affected products

Products and packages named in the record

VendorProductVersion / packageStatus
CiscoCisco SD-WAN Solutionn/aListed
Weakness

CWE details

CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.

CWE-119 · source CWE mapping

Improper Restriction of Operations within the Bounds of a Memory Buffer

Improper Restriction of Operations within the Bounds of a Memory Buffer represents a recurring weakness pattern that can create exploitable paths when design, validation, or implementation controls are missing.