PT-2021-1917 · Cisco · Cisco Ios Xr

Published

2021-02-03

·

Updated

2021-02-08

·

CVE-2021-1370

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Cisco IOS XR Software versions for the Cisco 8000 Series Routers and Network Convergence System 540 Series Routers running NCS540L software images (affected versions not specified)
Description A vulnerability in a CLI command could allow an authenticated, local attacker to elevate their privilege to root. The vulnerability is due to insufficient validation of command line arguments. An attacker could exploit this vulnerability by authenticating to the device and entering a crafted command at the prompt. A successful exploit could allow an attacker with low-level privileges to escalate their privilege level to root.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability. However, it is mentioned that Cisco has released software updates that address this vulnerability. As a temporary workaround, consider restricting access to the CLI command until a patch is available. Avoid using crafted commands at the prompt until the issue is resolved.

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2021-00707
CVE-2021-1370

Affected Products

Cisco Ios Xr