PT-2021-4048 · Cisco · Cisco Ios Xr
Published
2021-09-08
·
Updated
2023-09-25
·
CVE-2021-34718
CVSS v2.0
8.5
High
| Vector | AV:N/AC:L/Au:S/C:C/I:C/A:N |
Name of the Vulnerable Software and Affected Versions
Cisco IOS XR Software (affected versions not specified)
Description
A vulnerability in the SSH Server process could allow an authenticated, remote attacker to overwrite and read arbitrary files on the local device. This issue is due to insufficient input validation of arguments supplied by the user for a specific file transfer method. An attacker with lower-level privileges could exploit this by specifying Secure Copy Protocol (SCP) parameters when authenticating to a device, potentially elevating their privileges and accessing files they should not have access to.
Recommendations
For Cisco IOS XR Software, update to a version that includes the fix for this issue, as software updates have been released by Cisco to address this vulnerability.
As a temporary workaround, consider restricting access to the Secure Copy Protocol (SCP) parameters to minimize the risk of exploitation.
Avoid using the SCP file transfer method until the issue is resolved.
Fix
Argument Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cisco Ios Xr