Active Debug Code in Cisco Systems, Inc products - CVE-2021-1398

 

Active Debug Code in Cisco Systems, Inc products - CVE-2021-1398

Published: March 29, 2021


Vulnerability identifier: #VU51763
CSH Severity: Low
CVSS v4: 7 [CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-1398
CWE-ID: CWE-489
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local attacker to execute arbitrary code on the system.

The vulnerability exists due to incorrect validations of specific function arguments that are passed to the boot script. An attacker with physical access can tamper with a specific file, execute unsigned code at boot time and bypass the image verification check in the secure boot process of the affected device.


Affected software

Integrated Services Virtual Routers
Cloud Services Router 1000V Series
Cisco IOS XE

How to mitigate CVE-2021-1398

Install updates from vendor's website.

Cisco IOS XE - addressed in versions 16.6.8.9, 16.6.9, 16.9.5.120, 16.9.6, 16.12.5, 17.1.3, 17.2.1.64, 17.2.2, 17.3.0.194, 17.3.1, 17.3.1w, 17.3.1x, 17.3.1a, 17.3.2, 17.3.2a, 17.3.3, 17.4.0.61, 17.4.0.62, 17.4.1, 17.4.1a, 17.4.1b

External References

Related Security Bulletins