Improper Verification of Cryptographic Signature in Cisco Systems, Inc products - CVE-2021-1376

 

Improper Verification of Cryptographic Signature in Cisco Systems, Inc products - CVE-2021-1376

Published: March 29, 2021


Vulnerability identifier: #VU51762
CSH Severity: Low
CVSS v4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-1376
CWE-ID: CWE-347
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to compromise the target system.

The vulnerability exists in the fast reload feature due to an improper check on the area of code that manages the verification of boot configuration files during the initial fast reload boot process. A local administrator can execute arbitrary code on the underlying operating system.


Affected software

Cisco Catalyst 3850 Series Switches
Cisco Catalyst 9300 Series Switches
Cisco Catalyst 9300L Series Switches
Cisco IOS XE

How to mitigate CVE-2021-1376

Install updates from vendor's website.

Cisco IOS XE - addressed in versions 16.6.8.21, 16.6.9, 16.9.6.72, 16.9.7, 16.12.4.42, 16.12.5, 16.12.5a, 17.1.3, 17.2.1.177, 17.3.0.211, 17.3.1, 17.3.1w, 17.3.1x, 17.3.1a, 17.3.1.10, 17.3.2, 17.3.2a, 17.3.3, 17.4.0.73, 17.4.1, 17.4.1a, 17.4.1b

External References

Related Security Bulletins