#VU53747 Improper Authorization in Cisco Systems, Inc products - CVE-2021-1540
Published: June 2, 2021
Cisco ASR 5000 Series
Cisco Virtualized Packet Core
Cisco StarOS
Cisco Systems, Inc
Description
The vulnerability allows a remote user to gain unauthorized access to the system.
The vulnerability exists due to incorrect authorization of non-interactive CLI commands in the authorization process of Cisco ASR 5000 Series Software (StarOS). A remote authenticated user can send a specially crafted SSH request to an affected device, bypass the nocli option and execute certain CLI commands.