Inclusion of Sensitive Information in Log Files in Cisco Systems, Inc products - CVE-2021-1442
Published: March 24, 2021
Vulnerability details
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists in a diagnostic command for the Plug-and-Play (PnP) subsystem of Cisco IOS XE Software. A local low-privileged user can run the diagnostic CLI show pnp profile when a specific PnP listener is enabled on the device and obtain a privileged authentication token. This token can be used to send crafted PnP messages and execute privileged commands on the targeted system.
Affected software
Cisco Catalyst 9600 Series Switches
Cisco Catalyst 9200 Series Switches
Cisco 1100 Series Industrial Integrated Services Routers
Cisco Catalyst 9400 Series Switches
Cisco Catalyst 9500 Series Switches
Cisco Catalyst 9300 Series Switches
Cisco 1000 Series Integrated Services Routers
Cisco 4000 Series Integrated Services Routers
Cisco Catalyst 3650 Series Switches
Cisco Cloud Services Router 1000V Series
Cisco ASR 1000 Series Aggregation Services Routers
Allen-Bradley Stratix 5400 Industrial Ethernet Switches
Allen-Bradley Stratix 5410 Industrial Distribution Switches
Allen-Bradley Stratix 5700 Industrial Managed Ethernet Switches
Allen-Bradley Stratix 8000 Modular Managed Ethernet Switches
Stratix 5800
Cisco IOS XE