OS Command Injection in Cisco Embedded Services 3300 Series Switches and Cisco IOS XE - CVE-2021-1452
Published: March 24, 2021
Vulnerability details
The vulnerability allows a local user to execute arbitrary shell commands on the target system.
The vulnerability exists in ROM Monitor (ROMMON) due to incorrect validations of specific function arguments passed to a boot script when specific ROMMON variables are set.An attacker with physical access to the system can execute unsigned code at system boot time.
Affected software
Allen-Bradley Stratix 5400 Industrial Ethernet Switches
Allen-Bradley Stratix 5410 Industrial Distribution Switches
Allen-Bradley Stratix 5700 Industrial Managed Ethernet Switches
Allen-Bradley Stratix 8000 Modular Managed Ethernet Switches
Stratix 5800
Cisco IOS XE