OS Command Injection in Cisco Systems, Inc products - CVE-2021-1441

 

OS Command Injection in Cisco Systems, Inc products - CVE-2021-1441

Published: March 30, 2021


Vulnerability identifier: #VU51785
CSH Severity: Low
CVSS v4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-1441
CWE-ID: CWE-78
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to execute arbitrary shell commands on the target system.

The vulnerability exists due to incorrect validations of parameters passed to a diagnostic script that is executed when the device boots up. A local administrator can tamper with an executable file stored on a device and execute arbitrary OS commands on the target system.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.


Affected software

Cisco 1100 Series Industrial Integrated Services Routers
ESR6300 Embedded Series Routers
Cisco IOS XE

How to mitigate CVE-2021-1441

Install updates from vendor's website.

Cisco IOS XE - addressed in versions 16.9.6.75, 16.9.7, 16.12.4.39, 16.12.5, 17.1.3, 17.3.0.188, 17.3.1, 17.4.0.56, 17.4.1

External References

Related Security Bulletins