OS Command Injection in Cisco Embedded Services 3300 Series Switches and Cisco IOS XE - CVE-2021-1452

 

OS Command Injection in Cisco Embedded Services 3300 Series Switches and Cisco IOS XE - CVE-2021-1452

Published: March 24, 2021


Vulnerability identifier: #VU51709
CSH Severity: Low
CVSS v4: 7 [CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-1452
CWE-ID: CWE-78
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to execute arbitrary shell commands on the target system.

The vulnerability exists in ROM Monitor (ROMMON) due to incorrect validations of specific function arguments passed to a boot script when specific ROMMON variables are set.An attacker with physical access to the system can execute unsigned code at system boot time.


Affected software

Cisco Embedded Services 3300 Series Switches
Allen-Bradley Stratix 5400 Industrial Ethernet Switches
Allen-Bradley Stratix 5410 Industrial Distribution Switches
Allen-Bradley Stratix 5700 Industrial Managed Ethernet Switches
Allen-Bradley Stratix 8000 Modular Managed Ethernet Switches
Stratix 5800
Cisco IOS XE

How to mitigate CVE-2021-1452

Install updates from vendor's website.

Stratix 5800 - update to 17.04.01

External References

Related Security Bulletins