← Back

CVE-2021-1488

nvd nist
Published: Apr 29, 2021Modified: Nov 21, 2024

JSON object

Loading...
6.7
Vector
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Exploitability: 0.8 / Impact: 5.9
Source: NVD

Description

A vulnerability in the upgrade process of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker to inject commands that could be executed with root privileges on the underlying operating system (OS). This vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by uploading a crafted upgrade package file to an affected device. A successful exploit could allow the attacker to inject commands that could be executed with root privileges on the underlying OS.

Affected (5)

2 products
Firepower Threat Defense
Configuration A
5 vulnerable · 8 platform
Vulnerable SoftwareAffected Versions
Cisco
From 9.13 to 9.13.1.21
From 9.14 to 9.14.2.13
From 9.15 to 9.15.1.10
Cisco
From 6.5.0 to 6.6.4
From 6.7.0 to 6.7.0.2
Running on/withPlatform Versions
Cisco
Firepower 1010
All versions
Cisco
Firepower 1120
All versions
Cisco
Firepower 1140
All versions
Cisco
Firepower 1150
All versions
Cisco
Firepower 2110
All versions
Cisco
Firepower 2120
All versions
Cisco
Firepower 2130
All versions
Cisco
Firepower 2140
All versions

Timeline

No history available yet.