OS Command Injection in Cisco Systems, Inc products - CVE-2021-1443
Published: March 30, 2021
Vulnerability details
The vulnerability allows a remote user to execute arbitrary shell commands on the target system.
The vulnerability exists due to improper input validation in the web UI. A remote administrator can pass specially crafted data to the application and execute arbitrary OS commands on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
Affected software
Cisco ASR 1000 Series Aggregation Services Routers
Cisco 1000 Series Integrated Services Routers
Cisco Catalyst 9300 Series Switches
Cisco Catalyst 9500 Series Switches
Cisco Catalyst 9200 Series Switches
Cisco Catalyst 9800 Series Wireless Controllers
Allen-Bradley Stratix 5400 Industrial Ethernet Switches
Allen-Bradley Stratix 5410 Industrial Distribution Switches
Allen-Bradley Stratix 5700 Industrial Managed Ethernet Switches
Allen-Bradley Stratix 8000 Modular Managed Ethernet Switches
Stratix 5800
Cisco IOS XE
How to mitigate CVE-2021-1443
Stratix 5800 - update to 17.04.01