PT-2021-2989 · Cisco · Cisco Asyncos
Jakub Bros
·
Published
2021-05-05
·
Updated
2021-05-14
·
CVE-2021-1447
CVSS v2.0
7.2
High
| Vector | AV:L/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Cisco AsyncOS for Cisco Content Security Management Appliance (affected versions not specified)
Description
The issue is due to a procedural flaw in the password generation algorithm, allowing an authenticated, local attacker to elevate their privileges to root. An attacker could exploit this by enabling specific Administrator-only features and connecting to the appliance through the CLI with elevated privileges, potentially executing arbitrary commands as root and accessing the underlying operating system. The attacker must have valid Administrator credentials to exploit this issue.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Improper Privilege Management
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cisco Asyncos