#VU51785 OS Command Injection in Cisco Systems, Inc products - CVE-2021-1441

 

#VU51785 OS Command Injection in Cisco Systems, Inc products - CVE-2021-1441

Published: March 30, 2021


Vulnerability identifier: #VU51785
Vulnerability risk: Low
CVSSv4.0: CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2021-1441
CWE-ID: CWE-78
Exploitation vector: Local access
Exploit availability: No public exploit available
Vulnerable software:
Cisco IOS XE
Cisco 1100 Series Industrial Integrated Services Routers
ESR6300 Embedded Series Routers
Software vendor:
Cisco Systems, Inc

Description

The vulnerability allows a local user to execute arbitrary shell commands on the target system.

The vulnerability exists due to incorrect validations of parameters passed to a diagnostic script that is executed when the device boots up. A local administrator can tamper with an executable file stored on a device and execute arbitrary OS commands on the target system.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.


Remediation

Install updates from vendor's website.

External links