Improper Privilege Management in Cisco AsyncOS for Cisco Content Security Management Appliance - CVE-2021-1447

 

Improper Privilege Management in Cisco AsyncOS for Cisco Content Security Management Appliance - CVE-2021-1447

Published: May 6, 2021


Vulnerability identifier: #VU52906
CSH Severity: Low
CVSS v4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-1447
CWE-ID: CWE-269
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to escalate privileges.

The vulnerability exists due to a procedural flaw in the password generation algorithm. A local user can enable specific Administrator-only features and connect to the appliance through the CLI with elevated privileges.

Successful exploitation of the vulnerability may allow execution of arbitrary code with root privileges.


Affected software

Cisco AsyncOS for Cisco Content Security Management Appliance

How to mitigate CVE-2021-1447

Install updates from vendor's website.

Cisco AsyncOS for Cisco Content Security Management Appliance - addressed in versions 12.8.1 002, 13.8.1 068

External References

Related Security Bulletins