Command Injection in Cisco Systems, Inc products - CVE-2021-1448
Published: April 29, 2021
Vulnerability identifier: #VU52740
CSH Severity: Low
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-1448
CWE-ID: CWE-77
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local user to execute arbitrary commands on the target system.
The vulnerability exists due to improper input validation in the CLI. A local user can pass specially crafted data to the application and execute arbitrary commands on the target system.
Affected software
Cisco Firewall Threat Defense (FTD)
Cisco Firepower 9300 Security Appliance
Cisco Firepower 4100 Series Next-Generation Firewall
Cisco Firepower 9300 Security Appliance
Cisco Firepower 4100 Series Next-Generation Firewall
How to mitigate CVE-2021-1448
Install updates from vendor's website.
Cisco Firewall Threat Defense (FTD) - addressed in versions 6.4.0.10, 6.4.0.12, 6.5.0.5, 6.6.1, 6.6.4, 6.7.0.2