Active Debug Code in Cisco Systems, Inc products - CVE-2021-1391
Published: March 29, 2021
Vulnerability details
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to the presence of development testing and verification scripts that remained on the device in the dragonite debugger. A local administrator can bypass the consent token mechanism with the residual scripts on the affected device and escalate from privilege level 15 to root privilege.
Affected software
Cisco Catalyst IE3200 Rugged Series
Cisco Catalyst IE3300 Rugged Series
Cisco Catalyst IE3400 Rugged Series
Cisco Catalyst IE3400 Heavy Duty Series
Cisco IOS XE
Cisco IOS
How to mitigate CVE-2021-1391
Cisco IOS - addressed in versions 15.2(7)E4, 15.2(7.1.0p)E4, 15.2(8.0.18p)E, 15.2(8.0.28j)E, 16.9.6.123, 16.9.7, 16.12.3.49, 16.12.4, 16.12.4a, 16.12.5, 16.12.5a, 17.1.3, 17.3.0.188, 17.3.1, 17.3.1w, 17.3.1x, 17.3.1a, 17.3.2, 17.3.2a, 17.3.3, 17.4.0.56, 17.4.1, 17.4.1a, 17.4.1b