#VU51709 OS Command Injection in Cisco Embedded Services 3300 Series Switches and Cisco IOS XE - CVE-2021-1452

 

#VU51709 OS Command Injection in Cisco Embedded Services 3300 Series Switches and Cisco IOS XE - CVE-2021-1452

Published: March 24, 2021


Vulnerability identifier: #VU51709
Vulnerability risk: Low
CVSSv4.0: CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2021-1452
CWE-ID: CWE-78
Exploitation vector: Local access
Exploit availability: No public exploit available
Vulnerable software:
Cisco Embedded Services 3300 Series Switches
Cisco IOS XE
Software vendor:
Cisco Systems, Inc

Description

The vulnerability allows a local user to execute arbitrary shell commands on the target system.

The vulnerability exists in ROM Monitor (ROMMON) due to incorrect validations of specific function arguments passed to a boot script when specific ROMMON variables are set.An attacker with physical access to the system can execute unsigned code at system boot time.


Remediation

Install updates from vendor's website.

External links