CVE-2021-1528
7.8
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 1.8 / Impact: 5.9
Source: NVD
Description
A vulnerability in the CLI of Cisco SD-WAN Software could allow an authenticated, local attacker to gain elevated privileges on an affected system. This vulnerability exists because the affected software does not properly restrict access to privileged processes. An attacker could exploit this vulnerability by invoking a privileged process in the affected system. A successful exploit could allow the attacker to perform actions with the privileges of the root user.
Affected (22)
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| From 20.4 to 20.4.2 | |
| From 20.4 to 20.4.2 |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| From 20.4 to 20.4.2 |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| From 20.4 to 20.4.2 |
| Running on/with | Platform Versions |
|---|---|
Cisco Vedge 100 | All versions |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| From 20.4 to 20.4.2 |
| Running on/with | Platform Versions |
|---|---|
Cisco Vedge 1000 | All versions |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| From 20.4 to 20.4.2 |
| Running on/with | Platform Versions |
|---|---|
Cisco Vedge 100m | All versions |
Configuration G
| Vulnerable Software | Affected Versions |
|---|---|
| From 20.4 to 20.4.2 |
| Running on/with | Platform Versions |
|---|---|
Cisco Vedge 100wm | All versions |
Configuration H
| Vulnerable Software | Affected Versions |
|---|---|
| From 20.4 to 20.4.2 |
| Running on/with | Platform Versions |
|---|---|
Cisco Vedge 2000 | All versions |
Configuration I
| Vulnerable Software | Affected Versions |
|---|---|
| From 20.4 to 20.4.2 |
| Running on/with | Platform Versions |
|---|---|
Cisco Vedge 5000 | All versions |
Configuration J
| Vulnerable Software | Affected Versions |
|---|---|
| From 20.4 to 20.4.2 |
| Running on/with | Platform Versions |
|---|---|
Cisco Vedge 100b | All versions |
Configuration K
| Vulnerable Software | Affected Versions |
|---|---|
| From 20.4 to 20.4.2 |
| Running on/with | Platform Versions |
|---|---|
Cisco Vedge Cloud | All versions |
References (2)
Source: psirt@cisco.com
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Timeline
No history available yet.