PT-2021-3276 · Cisco · Cisco Sd-Wan

Published

2021-05-05

·

Updated

2023-10-16

·

CVE-2021-1514

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Cisco SD-WAN Software (affected versions not specified)
Description The issue is related to insufficient input validation on certain CLI commands, which could allow an authenticated, local attacker to inject arbitrary commands and execute them with Administrator privileges on the underlying operating system. An attacker must be authenticated as a low-privileged user to execute the affected commands. A successful exploit could allow the attacker to execute commands with Administrator privileges.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

OS Command Injection

Command Injection

Weakness Enumeration

Related Identifiers

BDU:2021-03040
CVE-2021-1514

Affected Products

Cisco Sd-Wan