Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2021-1371


A vulnerability in the role-based access control of Cisco IOS XE SD-WAN Software could allow an authenticated, local attacker with read-only privileges to obtain administrative privileges by using the console port when the device is in the default SD-WAN configuration. This vulnerability occurs because the default configuration is applied for console authentication and authorization. An attacker could exploit this vulnerability by connecting to the console port and authenticating as a read-only user. A successful exploit could allow a user with read-only permissions to access administrative privileges.


Published

2021-03-24T21:15:11.833

Last Modified

2024-11-21T05:44:12.110

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 6.6 (MEDIUM)

CVSSv2 Vector

AV:L/AC:L/Au:N/C:C/I:C/A:C

  • Access Vector: LOCAL
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: COMPLETE
  • Integrity Impact: COMPLETE
  • Availability Impact: COMPLETE
Exploitability Score

3.9

Impact Score

10.0

Weaknesses
  • Type: Primary
    CWE-269

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System cisco ios_xe_sd-wan 17.2.0 Yes
Application cisco cloud_services_router_1000v - No
Hardware cisco 1100_integrated_services_router - No
Hardware cisco 1101_integrated_services_router - No
Hardware cisco 1109_integrated_services_router - No
Hardware cisco 1111x_integrated_services_router - No
Hardware cisco 111x_integrated_services_router - No
Hardware cisco 1120_integrated_services_router - No
Hardware cisco 1160_integrated_services_router - No
Hardware cisco 4221_integrated_services_router - No
Hardware cisco 4321_integrated_services_router - No
Hardware cisco 4331_integrated_services_router - No
Hardware cisco 4351_integrated_services_router - No
Hardware cisco 4431_integrated_services_router - No
Hardware cisco 4451_integrated_services_router - No
Hardware cisco 4461_integrated_services_router - No
Hardware cisco asr_1000 - No

References