PT-2021-2494 · Cisco · Cisco Ios Xe Sd-Wan+1

James Spadaro Iii

·

Published

2021-03-24

·

Updated

2021-03-29

·

CVE-2021-1436

CVSS v2.0

4.7

Medium

VectorAV:L/AC:M/Au:N/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions: Cisco IOS XE SD-WAN Software (affected versions not specified)
Description: The issue is related to insufficient validation of user-supplied input in the command-line interface of the software, allowing an authenticated, local attacker to conduct path traversal attacks. This could enable the attacker to obtain read access to sensitive files on the affected system by sending a crafted request. The vulnerability is due to incorrect restriction of the directory path name with limited access.
Recommendations: For all affected versions, update to the latest software version released by Cisco that addresses this issue. As a temporary workaround, consider restricting access to sensitive files and directories to minimize the risk of exploitation. Avoid using the vulnerable CLI interface until the issue is resolved with a software update.

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2021-01870
CVE-2021-1436

Affected Products

Cisco Ios Xe Sd-Wan
Cisco Ios Xe