Multiple vulnerabilities in the authorization process of Cisco ASR 5000 Series Software (StarOS) could allow an authenticated, remote attacker to bypass authorization and execute a subset of CLI commands on an affected device. For more information about these vulnerabilities, see the Details section of this advisory.
2021-06-04T17:15:09.917
2024-11-21T05:44:34.820
Modified
CVSSv3.1: 8.1 (HIGH)
AV:N/AC:M/Au:S/C:P/I:P/A:P
6.8
6.4
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | cisco | staros | < 21.16.9 | Yes |
Operating System | cisco | staros | < 21.17.10 | Yes |
Operating System | cisco | staros | < 21.18.16 | Yes |
Operating System | cisco | staros | < 21.19.11 | Yes |
Operating System | cisco | staros | < 21.19.n7 | Yes |
Operating System | cisco | staros | < 21.20.8 | Yes |
Hardware | cisco | asr_5000 | - | No |
Hardware | cisco | asr_5500 | - | No |
Hardware | cisco | asr_5700 | - | No |
Application | cisco | virtualized_packet_core | - | Yes |