PT-2021-5012 · Cisco · Cisco Ios Xe Sd-Wan+1

Julien Legras

·

Published

2021-10-20

·

Updated

2023-09-26

·

CVE-2021-1529

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Cisco IOS XE SD-WAN Software (affected versions not specified)
Description A vulnerability in the CLI of Cisco IOS XE SD-WAN Software could allow an authenticated, local attacker to execute arbitrary commands with root privileges. The vulnerability is due to insufficient input validation by the system CLI. An attacker could exploit this vulnerability by authenticating to an affected device and submitting crafted input to the system CLI. A successful exploit could allow the attacker to execute commands on the underlying operating system with root privileges.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2021-05779
CVE-2021-1529

Affected Products

Cisco Ios Xe Sd-Wan
Cisco Ios Xe