Command Injection in Cisco Systems, Inc products - CVE-2021-34726

 

Command Injection in Cisco Systems, Inc products - CVE-2021-34726

Published: September 24, 2021


Vulnerability identifier: #VU56871
CSH Severity: Low
CVSS v4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-34726
CWE-ID: CWE-77
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to execute arbitrary commands on the target system.

The vulnerability exists due to improper input validation in the CLI. A local administrator can pass specially crafted data to the application and execute arbitrary commands on the target system.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.


Affected software

Cisco SD-WAN vBond Orchestrator
Cisco SD-WAN vEdge Cloud Router
Cisco SD-WAN vEdge Routers
Catalyst SD-WAN Manager (formerly SD-WAN vManage)
Catalyst SD-WAN Controller (formerly SD-WAN vSmart)
Cisco SD-WAN

How to mitigate CVE-2021-34726

Install updates from vendor's website.

Cisco SD-WAN - addressed in versions 18.4.6, 19.2.3, 20.1.1.2, 20.1.2, 20.3.1, 20.4.1, 20.5.1

External References

Related Security Bulletins