PT-2021-2493 · Cisco · Cisco Ios Xe Sd-Wan+1
Published
2021-03-24
·
Updated
2021-03-29
·
CVE-2021-1434
CVSS v2.0
6.6
Medium
| Vector | AV:L/AC:L/Au:N/C:N/I:C/A:C |
Name of the Vulnerable Software and Affected Versions:
Cisco IOS XE SD-WAN Software (affected versions not specified)
Description:
A vulnerability in the CLI of Cisco IOS XE SD-WAN Software could allow an authenticated, local attacker to overwrite arbitrary files in the underlying file system. This issue is due to insufficient validation of the parameters of a specific CLI command. An attacker could exploit this vulnerability by issuing that command with specific parameters, potentially allowing them to overwrite the content of any arbitrary file on the underlying host file system.
Recommendations:
For all affected versions, update to the latest software version that addresses this vulnerability, as provided by Cisco.
At the moment, there is no information about specific workarounds that address this vulnerability.
Fix
Files Accessible to External Parties
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cisco Ios Xe Sd-Wan
Cisco Ios Xe