Insufficiently protected credentials in Cisco Systems, Inc products - CVE-2021-1392

 

Insufficiently protected credentials in Cisco Systems, Inc products - CVE-2021-1392

Published: March 29, 2021


Vulnerability identifier: #VU51768
CSH Severity: Low
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-1392
CWE-ID: CWE-522
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to compromise the target system.

The vulnerability exists due to incorrect permissions are associated with the show cip security CLI command. A local user can use a specially crafted command to retrieve the password for CIP and reconfigure the device.


Affected software

Cisco Embedded Services 3300 Series Switches
Allen-Bradley Stratix 5400 Industrial Ethernet Switches
Allen-Bradley Stratix 5410 Industrial Distribution Switches
Allen-Bradley Stratix 5700 Industrial Managed Ethernet Switches
Allen-Bradley Stratix 8000 Modular Managed Ethernet Switches
Stratix 5800
Cisco IOS
Cisco IOS XE

How to mitigate CVE-2021-1392

Install updates from vendor's website.

Cisco IOS - addressed in versions 8.5.164.27, 8.5.171.0, 15.2(7)E4, 15.2(7.0.16j)E4, 15.2(7.1.0p)E4, 15.3.3 JF14, 16.12.4.40, 16.12.5, 16.12.5a, 17.1.3, 17.2.1.177, 17.3.0.188, 17.3.1, 17.3.1w, 17.3.1x, 17.3.1a, 17.3.2, 17.3.2a, 17.3.3, 17.4.0.56, 17.4.1, 17.4.1a, 17.4.1b
Cisco IOS XE - addressed in versions 8.5.164.27, 8.5.171.0, 15.2.7 E4, 15.2.7.0.16j E4, 15.2.7.1.0p E4, 15.3.3 JF14, 16.12.4.40, 16.12.5, 16.12.5a, 17.1.3, 17.2.1.177, 17.3.0.188, 17.3.1, 17.3.1w, 17.3.1x, 17.3.1a, 17.3.2, 17.3.2a, 17.3.3, 17.4.0.56, 17.4.1, 17.4.1a, 17.4.1b
Stratix 5800 - update to 17.04.01

External References

Related Security Bulletins