#VU51761 Improper Verification of Cryptographic Signature in Cisco Systems, Inc products - CVE-2021-1375
Published: March 29, 2021
Cisco IOS XE
Cisco Catalyst 3850 Series Switches
Cisco Catalyst 9300 Series Switches
Cisco Catalyst 9300L Series Switches
Cisco Systems, Inc
Description
The vulnerability allows a local user to compromise the target system.
The vulnerability exists in the fast reload feature due to incorrect validations of parameters passed to a configuration file that is executed when the device boots up. A local administrator can tamper with a configuration file stored on a device, execute unsigned code at boot time and bypass the software image verification check.