Arbitrary File Overwrite in Cisco IOS XE SD-WAN Software



Published: 2021-09-24
Risk Low
Patch available YES
Number of vulnerabilities 1
CVE-ID CVE-2021-1612
CWE-ID CWE-61
Exploitation vector Local
Public exploit N/A
Vulnerable software
Subscribe
Cisco IOS XE SD-WAN
Other software / Other software solutions

Vendor Cisco Systems, Inc

Security Bulletin

This security bulletin contains one low risk vulnerability.

1) UNIX symbolic link following

EUVDB-ID: #VU56868

Risk: Low

CVSSv3.1: 4.8 [CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N/E:U/RL:O/RC:C]

CVE-ID: CVE-2021-1612

CWE-ID: CWE-61 - UNIX Symbolic Link (Symlink) Following

Exploit availability: No

Description

The vulnerability allows a local user to overwrite arbitrary files.

The vulnerability exists due to improper access controls on files within the local file system. A local user can place a symbolic link in a specific location and overwrite arbitrary files on an affected device.

Mitigation

Install updates from vendor's website.

Vulnerable software versions

Cisco IOS XE SD-WAN: 17.3.1

External links

http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sd-wan-GjR5pGOm


Q & A

Can this vulnerability be exploited remotely?

No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.



###SIDEBAR###