Active Debug Code in Cisco Systems, Inc products - CVE-2021-1391

 

Active Debug Code in Cisco Systems, Inc products - CVE-2021-1391

Published: March 29, 2021


Vulnerability identifier: #VU51765
CSH Severity: Low
CVSS v4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-1391
CWE-ID: CWE-489
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to escalate privileges on the system.

The vulnerability exists due to the presence of development testing and verification scripts that remained on the device in the dragonite debugger. A local administrator can bypass the consent token mechanism with the residual scripts on the affected device and escalate from privilege level 15 to root privilege.


Affected software

Cisco Embedded Services 3300 Series Switches
Cisco Catalyst IE3200 Rugged Series
Cisco Catalyst IE3300 Rugged Series
Cisco Catalyst IE3400 Rugged Series
Cisco Catalyst IE3400 Heavy Duty Series
Cisco IOS XE
Cisco IOS

How to mitigate CVE-2021-1391

Install updates from vendor's website.

Cisco IOS XE - addressed in versions 15.2.7 E4, 15.2.7.1.0p E4, 15.2.8.0.18p E, 15.2.8.0.28j E, 16.9.6.123, 16.9.7, 16.12.3.49, 16.12.4, 16.12.4a, 16.12.5, 16.12.5a, 17.1.3, 17.3.0.188, 17.3.1, 17.3.1w, 17.3.1x, 17.3.1a, 17.3.2, 17.3.2a, 17.3.3, 17.4.0.56, 17.4.1, 17.4.1a, 17.4.1b
Cisco IOS - addressed in versions 15.2(7)E4, 15.2(7.1.0p)E4, 15.2(8.0.18p)E, 15.2(8.0.28j)E, 16.9.6.123, 16.9.7, 16.12.3.49, 16.12.4, 16.12.4a, 16.12.5, 16.12.5a, 17.1.3, 17.3.0.188, 17.3.1, 17.3.1w, 17.3.1x, 17.3.1a, 17.3.2, 17.3.2a, 17.3.3, 17.4.0.56, 17.4.1, 17.4.1a, 17.4.1b

External References

Related Security Bulletins