← Back

CVE-2021-1442

nvd nist
Published: Mar 24, 2021Modified: Nov 21, 2024

JSON object

Loading...
7.8
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 1.8 / Impact: 5.9
Source: NVD

Description

A vulnerability in a diagnostic command for the Plug-and-Play (PnP) subsystem of Cisco IOS XE Software could allow an authenticated, local attacker to elevate privileges to the level of an Administrator user (level 15) on an affected device. The vulnerability is due to insufficient protection of sensitive information. An attacker with low privileges could exploit this vulnerability by issuing the diagnostic CLI show pnp profile when a specific PnP listener is enabled on the device. A successful exploit could allow the attacker to obtain a privileged authentication token. This token can be used to send crafted PnP messages and execute privileged commands on the targeted system.

Affected (224)

Products: Cisco: Ios Xe
1 product
Ios Xe
Configuration A
224 vulnerable
Vulnerable SoftwareAffected Versions
Cisco
Version 16.1.1
Version 16.1.2
Version 16.1.3
Version 16.10.1
Version 16.10.1a
Version 16.10.1b
Version 16.10.1c
Version 16.10.1d
Version 16.10.1e
Version 16.10.1f
Version 16.10.1g
Version 16.10.1s
Version 16.10.2
Version 16.10.3
Version 16.11.1
Version 16.11.1a
Version 16.11.1b
Version 16.11.1c
Version 16.11.1s
Version 16.11.2
Version 16.12.1
Version 16.12.1a
Version 16.12.1c
Version 16.12.1s
Version 16.12.1t
Version 16.12.1w
Version 16.12.1x
Version 16.12.1y
Version 16.12.1z
Version 16.12.2
Version 16.12.2a
Version 16.12.2s
Version 16.12.2t
Version 16.12.3
Version 16.12.3a
Version 16.12.3s
Version 16.12.4
Version 16.12.4a
Version 16.2.1
Version 16.2.2
Version 16.3.10
Version 16.3.11
Version 16.3.1
Version 16.3.1a
Version 16.3.2
Version 16.3.3
Version 16.3.4
Version 16.3.5
Version 16.3.5b
Version 16.3.6
Version 16.3.7
Version 16.3.8
Version 16.3.9
Version 16.4.1
Version 16.4.2
Version 16.4.3
Version 16.5.1
Version 16.5.1a
Version 16.5.1b
Version 16.5.2
Version 16.5.3
Version 16.6.1
Version 16.6.2
Version 16.6.3
Version 16.6.4
Version 16.6.4a
Version 16.6.4s
Version 16.6.5
Version 16.6.5a
Version 16.6.5b
Version 16.6.6
Version 16.6.7
Version 16.6.7a
Version 16.6.8
Version 16.7.1
Version 16.7.1a
Version 16.7.1b
Version 16.7.2
Version 16.7.3
Version 16.7.4
Version 16.8.1
Version 16.8.1a
Version 16.8.1b
Version 16.8.1c
Version 16.8.1d
Version 16.8.1e
Version 16.8.1s
Version 16.8.2
Version 16.8.3
Version 16.9.1
Version 16.9.1a
Version 16.9.1b
Version 16.9.1c
Version 16.9.1d
Version 16.9.1s
Version 16.9.2
Version 16.9.2a
Version 16.9.2s
Version 16.9.3
Version 16.9.3a
Version 16.9.3h
Version 16.9.3s
Version 16.9.4
Version 16.9.4c
Version 16.9.5
Version 16.9.5f
Version 16.9.6
Version 17.1.1
Version 17.1.1a
Version 17.1.1s
Version 17.1.1t
Version 17.1.2
Version 17.2.1
Version 17.2.1a
Version 17.2.1r
Version 17.2.1v
Version 3.10.0ce
Version 3.10.0e
Version 3.10.1ae
Version 3.10.1e
Version 3.10.1se
Version 3.10.2e
Version 3.10.3e
Version 3.11.0e
Version 3.11.1ae
Version 3.11.1e
Version 3.11.2ae
Version 3.11.2e
Version 3.13.10s
Version 3.13.8s
Version 3.13.9s
Version 3.16.0as
Version 3.16.0bs
Version 3.16.0cs
Version 3.16.0s
Version 3.16.10as
Version 3.16.10s
Version 3.16.1as
Version 3.16.1s
Version 3.16.2as
Version 3.16.2bs
Version 3.16.2s
Version 3.16.3as
Version 3.16.3s
Version 3.16.4as
Version 3.16.4bs
Version 3.16.4cs
Version 3.16.4ds
Version 3.16.4es
Version 3.16.4gs
Version 3.16.4s
Version 3.16.5as
Version 3.16.5bs
Version 3.16.5s
Version 3.16.6bs
Version 3.16.6s
Version 3.16.7as
Version 3.16.7bs
Version 3.16.7s
Version 3.16.8s
Version 3.16.9s
Version 3.17.0s
Version 3.17.1as
Version 3.17.1s
Version 3.17.2s
Version 3.17.3s
Version 3.17.4s
Version 3.18.0as
Version 3.18.0s
Version 3.18.0sp
Version 3.18.1asp
Version 3.18.1bsp
Version 3.18.1csp
Version 3.18.1gsp
Version 3.18.1hsp
Version 3.18.1isp
Version 3.18.1s
Version 3.18.1sp
Version 3.18.2asp
Version 3.18.2s
Version 3.18.2sp
Version 3.18.3asp
Version 3.18.3bsp
Version 3.18.3s
Version 3.18.3sp
Version 3.18.4s
Version 3.18.4sp
Version 3.18.5sp
Version 3.18.6sp
Version 3.18.7sp
Version 3.18.8asp
Version 3.18.8sp
Version 3.6.10e
Version 3.6.3e
Version 3.6.4e
Version 3.6.5ae
Version 3.6.5be
Version 3.6.5e
Version 3.6.6e
Version 3.6.7ae
Version 3.6.7be
Version 3.6.7e
Version 3.6.8e
Version 3.6.9ae
Version 3.6.9e
Version 3.7.3e
Version 3.7.4e
Version 3.7.5e
Version 3.8.0e
Version 3.8.10e
Version 3.8.1e
Version 3.8.2e
Version 3.8.3e
Version 3.8.4e
Version 3.8.5ae
Version 3.8.5e
Version 3.8.6e
Version 3.8.7e
Version 3.8.8e
Version 3.8.9e
Version 3.9.0e
Version 3.9.1e
Version 3.9.2be
Version 3.9.2e

Timeline

No history available yet.