Missing XML Validation in Cisco AsyncOS for Secure Web Appliance - CVE-2021-1359
Published: July 8, 2021
Vulnerability details
The vulnerability allows a remote attacker to compromise the target system.
The vulnerability exists due to insufficient validation of user-supplied XML input for the web interface. A remote authenticated attacker can upload specially crafted XML configuration files to execute arbitrary commands on the underlying operating system and elevate privileges to root.