PT-2021-2449 · Cisco · Cisco Ios Xe Sd-Wan+1

Published

2021-03-24

·

Updated

2023-05-22

·

CVE-2021-1371

CVSS v2.0

7.2

High

VectorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: Cisco IOS XE SD-WAN Software (affected versions not specified)
Description: A vulnerability in the role-based access control of Cisco IOS XE SD-WAN Software could allow an authenticated, local attacker with read-only privileges to obtain administrative privileges by using the console port when the device is in the default SD-WAN configuration. This occurs because the default configuration is applied for console authentication and authorization. An attacker could exploit this vulnerability by connecting to the console port and authenticating as a read-only user, potentially allowing a user with read-only permissions to access administrative privileges.
Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Privilege Management

Weakness Enumeration

Related Identifiers

BDU:2021-01814
CVE-2021-1371

Affected Products

Cisco Ios Xe Sd-Wan
Cisco Ios Xe