Path traversal in Cisco Systems, Inc products - CVE-2021-1385
Published: March 25, 2021
Vulnerability identifier: #VU51731
CSH Severity: Low
CVSS v4: 8.5 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-1385
CWE-ID: CWE-22
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote user to perform directory traversal attacks.
The vulnerability exists due to the affected device does not properly validate URIs in IOx API requests. A remote administrator can send a specially crafted HTTP request and read or write arbitrary files on the underlying operating system.
Affected software
809 Industrial Integrated Services Routers
829 Industrial Integrated Services Routers
IC3000 Industrial Compute Gateway
CGR 1000 Compute Module
Stratix 5800
Cisco IOS
Cisco IOS XE
829 Industrial Integrated Services Routers
IC3000 Industrial Compute Gateway
CGR 1000 Compute Module
Stratix 5800
Cisco IOS
Cisco IOS XE
How to mitigate CVE-2021-1385
Install update from vendor's website.
IC3000 Industrial Compute Gateway - update to 1.4.1
CGR 1000 Compute Module - update to 1.9
Cisco IOS - addressed in versions 15.8.3 M2, 15.9.3 M4
Cisco IOS XE - addressed in versions 16.3.1, 17.3.2, 17.4.2, 17.5.1
Stratix 5800 - update to 16.12.01
CGR 1000 Compute Module - update to 1.9
Cisco IOS - addressed in versions 15.8.3 M2, 15.9.3 M4
Cisco IOS XE - addressed in versions 16.3.1, 17.3.2, 17.4.2, 17.5.1
Stratix 5800 - update to 16.12.01