← Back

CVE-2021-1145

nvd nist
Published: Jan 13, 2021Modified: Nov 21, 2024

JSON object

Loading...
6.5
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Exploitability: 2.8 / Impact: 3.6
Source: NVD

Description

A vulnerability in the Secure FTP (SFTP) of Cisco StarOS for Cisco ASR 5000 Series Routers could allow an authenticated, remote attacker to read arbitrary files on an affected device. To exploit this vulnerability, the attacker would need to have valid credentials on the affected device. The vulnerability is due to insecure handling of symbolic links. An attacker could exploit this vulnerability by sending a crafted SFTP command to an affected device. A successful exploit could allow the attacker to read arbitrary files on the affected device.

Affected (1)

Products: Cisco: Staros
1 product
Staros
Configuration A
1 vulnerable · 3 platform
Vulnerable SoftwareAffected Versions
Before 21.19.7
Running on/withPlatform Versions
Cisco
Asr 5000
All versions
Cisco
Asr 5500
All versions
Cisco
Asr 5700
All versions

Timeline

No history available yet.