Improper Authorization in Cisco Systems, Inc products - CVE-2021-1540

 

Improper Authorization in Cisco Systems, Inc products - CVE-2021-1540

Published: June 2, 2021


Vulnerability identifier: #VU53747
CSH Severity: Medium
CVSS v4: 7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-1540
CWE-ID: CWE-285
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to gain unauthorized access to the system.

The vulnerability exists due to incorrect authorization of non-interactive CLI commands in the authorization process of Cisco ASR 5000 Series Software (StarOS). A remote authenticated user can send a specially crafted SSH request to an affected device, bypass the nocli option and execute certain CLI commands.


Affected software

Cisco ASR 5000 Series
Cisco Virtualized Packet Core
Cisco StarOS

How to mitigate CVE-2021-1540

Install updates from vendor's website.

Cisco StarOS - addressed in versions 21.16.9, 21.17.10, 21.18.16, 21.19.n7, 21.20.8, 26.19.11

External References

Related Security Bulletins