Command Injection in Cisco Systems, Inc products - CVE-2021-1448

 

Command Injection in Cisco Systems, Inc products - CVE-2021-1448

Published: April 29, 2021


Vulnerability identifier: #VU52740
CSH Severity: Low
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-1448
CWE-ID: CWE-77
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to execute arbitrary commands on the target system.

The vulnerability exists due to improper input validation in the CLI. A local user can pass specially crafted data to the application and execute arbitrary commands on the target system.


Affected software

Cisco Firewall Threat Defense (FTD)
Cisco Firepower 9300 Security Appliance
Cisco Firepower 4100 Series Next-Generation Firewall

How to mitigate CVE-2021-1448

Install updates from vendor's website.

Cisco Firewall Threat Defense (FTD) - addressed in versions 6.4.0.10, 6.4.0.12, 6.5.0.5, 6.6.1, 6.6.4, 6.7.0.2

External References

Related Security Bulletins