← Back

CVE-2021-1385

nvd nist
Published: Mar 24, 2021Modified: Nov 21, 2024

JSON object

Loading...
6.5
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N
Exploitability: 1.2 / Impact: 5.2
Source: NVD

Description

A vulnerability in the Cisco IOx application hosting environment of multiple Cisco platforms could allow an authenticated, remote attacker to conduct directory traversal attacks and read and write files on the underlying operating system or host system. This vulnerability occurs because the device does not properly validate URIs in IOx API requests. An attacker could exploit this vulnerability by sending a crafted API request that contains directory traversal character sequences to an affected device. A successful exploit could allow the attacker to read or write arbitrary files on the underlying operating system.

Affected (57)

Products: Cisco: Ios, Ios Xe
2 products
Ios
Ios Xe
Configuration A
57 vulnerable
Vulnerable SoftwareAffected Versions
Cisco
Version 15.8(3)m2a
Version 15.8(3)m3
Version 15.8(3)m4
Version 15.8(3)m5
Version 15.8(3)m6
Version 15.9(3)m1
Version 15.9(3)m2
Version 15.9(3)m2a
Version 15.9(3)m3
Version 15.9(3)m
Cisco
Version 16.11.1
Version 16.11.1a
Version 16.11.1b
Version 16.11.1c
Version 16.11.1s
Version 16.11.2
Version 16.12.1
Version 16.12.1a
Version 16.12.1c
Version 16.12.1s
Version 16.12.1t
Version 16.12.1w
Version 16.12.1x
Version 16.12.1y
Version 16.12.1z1
Version 16.12.1z
Version 16.12.1za
Version 16.12.2
Version 16.12.2a
Version 16.12.2s
Version 16.12.2t
Version 16.12.3
Version 16.12.3a
Version 16.12.3s
Version 16.12.4
Version 16.12.4a
Version 16.12.5
Version 17.1.1
Version 17.1.1a
Version 17.1.1s
Version 17.1.1t
Version 17.1.2
Version 17.1.3
Version 17.2.1
Version 17.2.1a
Version 17.2.1r
Version 17.2.1v
Version 17.2.2
Version 17.3.1
Version 17.3.1a
Version 17.3.1w
Version 17.3.1x
Version 17.3.2
Version 17.3.2a
Version 17.4.1
Version 17.4.1a
Version 17.4.1b

Timeline

No history available yet.