Improper Verification of Cryptographic Signature in Cisco Systems, Inc products - CVE-2021-1375

 

Improper Verification of Cryptographic Signature in Cisco Systems, Inc products - CVE-2021-1375

Published: March 29, 2021


Vulnerability identifier: #VU51761
CSH Severity: Low
CVSS v4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-1375
CWE-ID: CWE-347
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to compromise the target system.

The vulnerability exists in the fast reload feature due to incorrect validations of parameters passed to a configuration file that is executed when the device boots up. A local administrator can tamper with a configuration file stored on a device, execute unsigned code at boot time and bypass the software image verification check.


Affected software

Cisco Catalyst 3850 Series Switches
Cisco Catalyst 9300 Series Switches
Cisco Catalyst 9300L Series Switches
Cisco IOS XE

How to mitigate CVE-2021-1375

Install updates from vendor's website.

Cisco IOS XE - addressed in versions 16.6.8, 16.6.9, 16.9.5, 16.9.5f, 16.9.6, 16.9.7, 16.12.1z, 16.12.2r, 16.12.3, 16.12.3s, 16.12.3a, 16.12.4, 16.12.4a, 16.12.5, 16.12.5a, 17.1.1s, 17.1.1t, 17.1.2, 17.1.3, 17.2.0.28, 17.2.0.46, 17.2.1, 17.2.1v, 17.2.1a, 17.2.1r, 17.2.2, 17.3.1, 17.3.1w, 17.3.1x, 17.3.1a, 17.3.2, 17.3.2a, 17.3.3, 17.4.1, 17.4.1a, 17.4.1b

External References

Related Security Bulletins