OS Command Injection in Cisco Systems, Inc products - CVE-2021-1443

 

OS Command Injection in Cisco Systems, Inc products - CVE-2021-1443

Published: March 30, 2021


Vulnerability identifier: #VU51780
CSH Severity: Low
CVSS v4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-1443
CWE-ID: CWE-78
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to execute arbitrary shell commands on the target system.

The vulnerability exists due to improper input validation in the web UI. A remote administrator can pass specially crafted data to the application and execute arbitrary OS commands on the target system.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.


Affected software

Cisco 2600 Series Multiservice Platforms
Cisco ASR 1000 Series Aggregation Services Routers
Cisco 1000 Series Integrated Services Routers
Cisco Catalyst 9300 Series Switches
Cisco Catalyst 9500 Series Switches
Cisco Catalyst 9200 Series Switches
Cisco Catalyst 9800 Series Wireless Controllers
Allen-Bradley Stratix 5400 Industrial Ethernet Switches
Allen-Bradley Stratix 5410 Industrial Distribution Switches
Allen-Bradley Stratix 5700 Industrial Managed Ethernet Switches
Allen-Bradley Stratix 8000 Modular Managed Ethernet Switches
Stratix 5800
Cisco IOS XE

How to mitigate CVE-2021-1443

Install updates from vendor's website.

Cisco IOS XE - addressed in versions 16.9.5.109, 16.9.6, 16.9.7, 16.12.3.51, 16.12.4, 16.12.4a, 16.12.5, 16.12.5a, 17.1.3, 17.2.1.52, 17.2.2, 17.3.0.189, 17.3.1, 17.3.1w, 17.3.1x, 17.3.1a, 17.3.2, 17.3.2a, 17.3.3, 17.4.0.56, 17.4.1, 17.4.1a, 17.4.1b
Stratix 5800 - update to 17.04.01

External References

Related Security Bulletins