PT-2021-2965 · Cisco · Cisco Waas

Published

2021-05-05

·

Updated

2021-05-17

·

CVE-2021-1438

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Cisco Wide Area Application Services Software (WAAS) (affected versions not specified)
Description The issue is related to improper input validation and authorization of specific commands that a user can execute within the Command Line Interface (CLI). An attacker could exploit this by authenticating to an affected device and issuing a specific set of commands, potentially allowing them to read arbitrary files they originally did not have permissions to access.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exposure of Resource to Wrong Sphere

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2021-02552
CVE-2021-1438

Affected Products

Cisco Waas