PT-2021-2449 · Cisco · Cisco Ios Xe Sd-Wan+1
Published
2021-03-24
·
Updated
2023-05-22
·
CVE-2021-1371
CVSS v2.0
7.2
High
| Vector | AV:L/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions:
Cisco IOS XE SD-WAN Software (affected versions not specified)
Description:
A vulnerability in the role-based access control of Cisco IOS XE SD-WAN Software could allow an authenticated, local attacker with read-only privileges to obtain administrative privileges by using the console port when the device is in the default SD-WAN configuration. This occurs because the default configuration is applied for console authentication and authorization. An attacker could exploit this vulnerability by connecting to the console port and authenticating as a read-only user, potentially allowing a user with read-only permissions to access administrative privileges.
Recommendations:
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Improper Privilege Management
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cisco Ios Xe Sd-Wan
Cisco Ios Xe