PT-2021-2989 · Cisco · Cisco Asyncos

Jakub Bros

·

Published

2021-05-05

·

Updated

2021-05-14

·

CVE-2021-1447

CVSS v2.0

7.2

High

VectorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Cisco AsyncOS for Cisco Content Security Management Appliance (affected versions not specified)
Description The issue is due to a procedural flaw in the password generation algorithm, allowing an authenticated, local attacker to elevate their privileges to root. An attacker could exploit this by enabling specific Administrator-only features and connecting to the appliance through the CLI with elevated privileges, potentially executing arbitrary commands as root and accessing the underlying operating system. The attacker must have valid Administrator credentials to exploit this issue.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Privilege Management

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2021-02577
CVE-2021-1447

Affected Products

Cisco Asyncos