Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2021-1391


A vulnerability in the dragonite debugger of Cisco IOS XE Software could allow an authenticated, local attacker to escalate from privilege level 15 to root privilege. The vulnerability is due to the presence of development testing and verification scripts that remained on the device. An attacker could exploit this vulnerability by bypassing the consent token mechanism with the residual scripts on the affected device. A successful exploit could allow the attacker to escalate from privilege level 15 to root privilege.


Published

2021-03-24T20:15:13.993

Last Modified

2024-11-21T05:44:14.797

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 5.1 (MEDIUM)

CVSSv2 Vector

AV:L/AC:L/Au:N/C:C/I:C/A:C

  • Access Vector: LOCAL
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: COMPLETE
  • Integrity Impact: COMPLETE
  • Availability Impact: COMPLETE
Exploitability Score

3.9

Impact Score

10.0

Weaknesses
  • Type: Primary
    CWE-489

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System cisco ios 12.2\(6\)i1 Yes
Operating System cisco ios 15.0\(2\)se13a Yes
Operating System cisco ios 15.1\(3\)svr1 Yes
Operating System cisco ios 15.1\(3\)svr2 Yes
Operating System cisco ios 15.1\(3\)svr3 Yes
Operating System cisco ios 15.1\(3\)svs Yes
Operating System cisco ios 15.1\(3\)svs1 Yes
Operating System cisco ios 15.2\(4\)ea10 Yes
Operating System cisco ios 15.2\(5\)e Yes
Operating System cisco ios 15.2\(5\)e1 Yes
Operating System cisco ios 15.2\(5\)e2 Yes
Operating System cisco ios 15.2\(5\)e2b Yes
Operating System cisco ios 15.2\(5\)e2c Yes
Operating System cisco ios 15.2\(5\)ea Yes
Operating System cisco ios 15.2\(5\)ex Yes
Operating System cisco ios 15.2\(5a\)e Yes
Operating System cisco ios 15.2\(5a\)e1 Yes
Operating System cisco ios 15.2\(5b\)e Yes
Operating System cisco ios 15.2\(5c\)e Yes
Operating System cisco ios 15.2\(6\)e Yes
Operating System cisco ios 15.2\(6\)e0a Yes
Operating System cisco ios 15.2\(6\)e0c Yes
Operating System cisco ios 15.2\(6\)e1 Yes
Operating System cisco ios 15.2\(6\)e1a Yes
Operating System cisco ios 15.2\(6\)e1s Yes
Operating System cisco ios 15.2\(6\)e2 Yes
Operating System cisco ios 15.2\(6\)e2a Yes
Operating System cisco ios 15.2\(6\)e2b Yes
Operating System cisco ios 15.2\(6\)e3 Yes
Operating System cisco ios 15.2\(6\)eb Yes
Operating System cisco ios 15.2\(7\)e Yes
Operating System cisco ios 15.2\(7\)e0a Yes
Operating System cisco ios 15.2\(7\)e0b Yes
Operating System cisco ios 15.2\(7\)e0s Yes
Operating System cisco ios 15.2\(7\)e1 Yes
Operating System cisco ios 15.2\(7\)e1a Yes
Operating System cisco ios 15.2\(7\)e2 Yes
Operating System cisco ios 15.2\(7\)e2a Yes
Operating System cisco ios 15.2\(7\)e2b Yes
Operating System cisco ios 15.2\(7\)e3 Yes
Operating System cisco ios 15.2\(7\)e3k Yes
Operating System cisco ios 15.2\(7a\)e0b Yes
Operating System cisco ios 15.2\(7b\)e0b Yes
Operating System cisco ios 15.3\(3\)jf13 Yes
Operating System cisco ios_xe 3.9.0e Yes
Operating System cisco ios_xe 3.9.1e Yes
Operating System cisco ios_xe 3.9.2be Yes
Operating System cisco ios_xe 3.9.2e Yes
Operating System cisco ios_xe 3.10.0ce Yes
Operating System cisco ios_xe 3.10.0e Yes
Operating System cisco ios_xe 3.10.1ae Yes
Operating System cisco ios_xe 3.10.1e Yes
Operating System cisco ios_xe 3.10.1se Yes
Operating System cisco ios_xe 3.10.2e Yes
Operating System cisco ios_xe 3.10.3e Yes
Operating System cisco ios_xe 3.11.0e Yes
Operating System cisco ios_xe 3.11.1ae Yes
Operating System cisco ios_xe 3.11.1e Yes
Operating System cisco ios_xe 3.11.2ae Yes
Operating System cisco ios_xe 3.11.2e Yes
Operating System cisco ios_xe 3.11.3ae Yes
Operating System cisco ios_xe 3.11.3e Yes
Operating System cisco ios_xe 16.8.1 Yes
Operating System cisco ios_xe 16.8.1a Yes
Operating System cisco ios_xe 16.8.1b Yes
Operating System cisco ios_xe 16.8.1c Yes
Operating System cisco ios_xe 16.8.1d Yes
Operating System cisco ios_xe 16.8.1e Yes
Operating System cisco ios_xe 16.8.1s Yes
Operating System cisco ios_xe 16.8.2 Yes
Operating System cisco ios_xe 16.8.3 Yes
Operating System cisco ios_xe 16.9.1 Yes
Operating System cisco ios_xe 16.9.1a Yes
Operating System cisco ios_xe 16.9.1b Yes
Operating System cisco ios_xe 16.9.1c Yes
Operating System cisco ios_xe 16.9.1d Yes
Operating System cisco ios_xe 16.9.1s Yes
Operating System cisco ios_xe 16.9.2 Yes
Operating System cisco ios_xe 16.9.2a Yes
Operating System cisco ios_xe 16.9.2s Yes
Operating System cisco ios_xe 16.9.3 Yes
Operating System cisco ios_xe 16.9.3a Yes
Operating System cisco ios_xe 16.9.3h Yes
Operating System cisco ios_xe 16.9.3s Yes
Operating System cisco ios_xe 16.9.4 Yes
Operating System cisco ios_xe 16.9.4c Yes
Operating System cisco ios_xe 16.9.5 Yes
Operating System cisco ios_xe 16.9.5f Yes
Operating System cisco ios_xe 16.9.6 Yes
Operating System cisco ios_xe 16.10.1 Yes
Operating System cisco ios_xe 16.10.1a Yes
Operating System cisco ios_xe 16.10.1b Yes
Operating System cisco ios_xe 16.10.1c Yes
Operating System cisco ios_xe 16.10.1d Yes
Operating System cisco ios_xe 16.10.1e Yes
Operating System cisco ios_xe 16.10.1f Yes
Operating System cisco ios_xe 16.10.1g Yes
Operating System cisco ios_xe 16.10.1s Yes
Operating System cisco ios_xe 16.10.2 Yes
Operating System cisco ios_xe 16.10.3 Yes
Operating System cisco ios_xe 16.11.1 Yes
Operating System cisco ios_xe 16.11.1a Yes
Operating System cisco ios_xe 16.11.1b Yes
Operating System cisco ios_xe 16.11.1c Yes
Operating System cisco ios_xe 16.11.1s Yes
Operating System cisco ios_xe 16.11.2 Yes
Operating System cisco ios_xe 16.12.1 Yes
Operating System cisco ios_xe 16.12.1a Yes
Operating System cisco ios_xe 16.12.1c Yes
Operating System cisco ios_xe 16.12.1s Yes
Operating System cisco ios_xe 16.12.1t Yes
Operating System cisco ios_xe 16.12.1w Yes
Operating System cisco ios_xe 16.12.1x Yes
Operating System cisco ios_xe 16.12.1y Yes
Operating System cisco ios_xe 16.12.1z Yes
Operating System cisco ios_xe 16.12.1za Yes
Operating System cisco ios_xe 16.12.2 Yes
Operating System cisco ios_xe 16.12.2a Yes
Operating System cisco ios_xe 16.12.2s Yes
Operating System cisco ios_xe 16.12.2t Yes
Operating System cisco ios_xe 16.12.3 Yes
Operating System cisco ios_xe 16.12.3a Yes
Operating System cisco ios_xe 16.12.3s Yes
Operating System cisco ios_xe 17.1.1 Yes
Operating System cisco ios_xe 17.1.1a Yes
Operating System cisco ios_xe 17.1.1s Yes
Operating System cisco ios_xe 17.1.1t Yes
Operating System cisco ios_xe 17.1.2 Yes
Operating System cisco ios_xe 17.2.1 Yes
Operating System cisco ios_xe 17.2.1a Yes
Operating System cisco ios_xe 17.2.1r Yes
Operating System cisco ios_xe 17.2.1v Yes
Operating System cisco ios_xe 17.2.2 Yes
Operating System cisco ios_xe 17.2.3 Yes

References