PT-2021-3792 · Cisco · Cisco Intersight Virtual Appliance

Published

2021-07-21

·

Updated

2022-10-24

·

CVE-2021-1618

CVSS v2.0

9.4

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:N
Name of the Vulnerable Software and Affected Versions Cisco Intersight Virtual Appliance (affected versions not specified)
Description The issue is due to insufficient input validation in the web-based management interface of Cisco Intersight Virtual Appliance, allowing an authenticated, remote attacker to conduct a path traversal or command injection attack. An attacker could exploit this by using the web-based management interface to execute a command using crafted input or upload a file altered using path traversal techniques. A successful exploit could allow the attacker to read and write arbitrary files or execute arbitrary commands as root on an affected system.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

OS Command Injection

Weakness Enumeration

Related Identifiers

BDU:2021-04067
CVE-2021-1618

Affected Products

Cisco Intersight Virtual Appliance