#VU50373 OS Command Injection in Cisco Systems, Inc products - CVE-2021-1370

 

#VU50373 OS Command Injection in Cisco Systems, Inc products - CVE-2021-1370

Published: February 4, 2021 / Updated: February 5, 2021


Vulnerability identifier: #VU50373
Vulnerability risk: Low
CVSSv4.0: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2021-1370
CWE-ID: CWE-78
Exploitation vector: Local access
Exploit availability: No public exploit available
Vulnerable software:
Cisco ASR 9000 Series Aggregation Services Routers
Cisco 8000 Series Routers
Cisco Network Convergence System 5000 Series
Software vendor:
Cisco Systems, Inc

Description

The vulnerability allows a local user to escalate privileges on the system.

The vulnerability exists due to improper input validation within the CLI command of Cisco IOS XR Software for the Cisco 8000 Series Routers and Network Convergence System 540 Series Routers running NCS540L software images. A local user can run a specially crafted command and execute arbitrary code on the system with root privileges.


Remediation

Install updates from vendor's website.

External links