OS Command Injection in Cisco Systems, Inc products - CVE-2021-1441
Published: March 30, 2021
Vulnerability details
The vulnerability allows a local user to execute arbitrary shell commands on the target system.
The vulnerability exists due to incorrect validations of parameters passed to a diagnostic script that is executed when the device boots up. A local administrator can tamper with an executable file stored on a device and execute arbitrary OS commands on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
Affected software
ESR6300 Embedded Series Routers
Cisco IOS XE