← Back

CVE-2021-1391

nvd nist
Published: Mar 24, 2021Modified: Nov 21, 2024

JSON object

Loading...
6.7
Vector
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Exploitability: 0.8 / Impact: 5.9
Source: NVD

Description

A vulnerability in the dragonite debugger of Cisco IOS XE Software could allow an authenticated, local attacker to escalate from privilege level 15 to root privilege. The vulnerability is due to the presence of development testing and verification scripts that remained on the device. An attacker could exploit this vulnerability by bypassing the consent token mechanism with the residual scripts on the affected device. A successful exploit could allow the attacker to escalate from privilege level 15 to root privilege.

Affected (134)

Products: Cisco: Ios, Ios Xe
2 products
Ios
Ios Xe
Configuration A
134 vulnerable
Vulnerable SoftwareAffected Versions
Cisco
Version 12.2(6)i1
Version 15.0(2)se13a
Version 15.1(3)svr1
Version 15.1(3)svr2
Version 15.1(3)svr3
Version 15.1(3)svs1
Version 15.1(3)svs
Version 15.2(4)ea10
Version 15.2(5)e1
Version 15.2(5)e2
Version 15.2(5)e2b
Version 15.2(5)e2c
Version 15.2(5)e
Version 15.2(5)ea
Version 15.2(5)ex
Version 15.2(5a)e1
Version 15.2(5a)e
Version 15.2(5b)e
Version 15.2(5c)e
Version 15.2(6)e0a
Version 15.2(6)e0c
Version 15.2(6)e1
Version 15.2(6)e1a
Version 15.2(6)e1s
Version 15.2(6)e2
Version 15.2(6)e2a
Version 15.2(6)e2b
Version 15.2(6)e3
Version 15.2(6)e
Version 15.2(6)eb
Version 15.2(7)e0a
Version 15.2(7)e0b
Version 15.2(7)e0s
Version 15.2(7)e1
Version 15.2(7)e1a
Version 15.2(7)e2
Version 15.2(7)e2a
Version 15.2(7)e2b
Version 15.2(7)e3
Version 15.2(7)e3k
Version 15.2(7)e
Version 15.2(7a)e0b
Version 15.2(7b)e0b
Version 15.3(3)jf13
Cisco
Version 16.10.1
Version 16.10.1a
Version 16.10.1b
Version 16.10.1c
Version 16.10.1d
Version 16.10.1e
Version 16.10.1f
Version 16.10.1g
Version 16.10.1s
Version 16.10.2
Version 16.10.3
Version 16.11.1
Version 16.11.1a
Version 16.11.1b
Version 16.11.1c
Version 16.11.1s
Version 16.11.2
Version 16.12.1
Version 16.12.1a
Version 16.12.1c
Version 16.12.1s
Version 16.12.1t
Version 16.12.1w
Version 16.12.1x
Version 16.12.1y
Version 16.12.1z
Version 16.12.1za
Version 16.12.2
Version 16.12.2a
Version 16.12.2s
Version 16.12.2t
Version 16.12.3
Version 16.12.3a
Version 16.12.3s
Version 16.8.1
Version 16.8.1a
Version 16.8.1b
Version 16.8.1c
Version 16.8.1d
Version 16.8.1e
Version 16.8.1s
Version 16.8.2
Version 16.8.3
Version 16.9.1
Version 16.9.1a
Version 16.9.1b
Version 16.9.1c
Version 16.9.1d
Version 16.9.1s
Version 16.9.2
Version 16.9.2a
Version 16.9.2s
Version 16.9.3
Version 16.9.3a
Version 16.9.3h
Version 16.9.3s
Version 16.9.4
Version 16.9.4c
Version 16.9.5
Version 16.9.5f
Version 16.9.6
Version 17.1.1
Version 17.1.1a
Version 17.1.1s
Version 17.1.1t
Version 17.1.2
Version 17.2.1
Version 17.2.1a
Version 17.2.1r
Version 17.2.1v
Version 17.2.2
Version 17.2.3
Version 3.10.0ce
Version 3.10.0e
Version 3.10.1ae
Version 3.10.1e
Version 3.10.1se
Version 3.10.2e
Version 3.10.3e
Version 3.11.0e
Version 3.11.1ae
Version 3.11.1e
Version 3.11.2ae
Version 3.11.2e
Version 3.11.3ae
Version 3.11.3e
Version 3.9.0e
Version 3.9.1e
Version 3.9.2be
Version 3.9.2e

Timeline

No history available yet.