7.2

CVE-2021-1391

A vulnerability in the dragonite debugger of Cisco IOS XE Software could allow an authenticated, local attacker to escalate from privilege level 15 to root privilege. The vulnerability is due to the presence of development testing and verification scripts that remained on the device. An attacker could exploit this vulnerability by bypassing the consent token mechanism with the residual scripts on the affected device. A successful exploit could allow the attacker to escalate from privilege level 15 to root privilege.

Data is provided by the National Vulnerability Database (NVD)
CiscoIos Version12.2(6)i1
CiscoIos Version15.0(2)se13a
CiscoIos Version15.1(3)svr1
CiscoIos Version15.1(3)svr2
CiscoIos Version15.1(3)svr3
CiscoIos Version15.1(3)svs
CiscoIos Version15.1(3)svs1
CiscoIos Version15.2(4)ea10
CiscoIos Version15.2(5)e
CiscoIos Version15.2(5)e1
CiscoIos Version15.2(5)e2
CiscoIos Version15.2(5)e2b
CiscoIos Version15.2(5)e2c
CiscoIos Version15.2(5)ea
CiscoIos Version15.2(5)ex
CiscoIos Version15.2(5a)e
CiscoIos Version15.2(5a)e1
CiscoIos Version15.2(5b)e
CiscoIos Version15.2(5c)e
CiscoIos Version15.2(6)e
CiscoIos Version15.2(6)e0a
CiscoIos Version15.2(6)e0c
CiscoIos Version15.2(6)e1
CiscoIos Version15.2(6)e1a
CiscoIos Version15.2(6)e1s
CiscoIos Version15.2(6)e2
CiscoIos Version15.2(6)e2a
CiscoIos Version15.2(6)e2b
CiscoIos Version15.2(6)e3
CiscoIos Version15.2(6)eb
CiscoIos Version15.2(7)e
CiscoIos Version15.2(7)e0a
CiscoIos Version15.2(7)e0b
CiscoIos Version15.2(7)e0s
CiscoIos Version15.2(7)e1
CiscoIos Version15.2(7)e1a
CiscoIos Version15.2(7)e2
CiscoIos Version15.2(7)e2a
CiscoIos Version15.2(7)e2b
CiscoIos Version15.2(7)e3
CiscoIos Version15.2(7)e3k
CiscoIos Version15.2(7a)e0b
CiscoIos Version15.2(7b)e0b
CiscoIos Version15.3(3)jf13
CiscoIos Xe Version3.9.0e
CiscoIos Xe Version3.9.1e
CiscoIos Xe Version3.9.2be
CiscoIos Xe Version3.9.2e
CiscoIos Xe Version3.10.0ce
CiscoIos Xe Version3.10.0e
CiscoIos Xe Version3.10.1ae
CiscoIos Xe Version3.10.1e
CiscoIos Xe Version3.10.1se
CiscoIos Xe Version3.10.2e
CiscoIos Xe Version3.10.3e
CiscoIos Xe Version3.11.0e
CiscoIos Xe Version3.11.1ae
CiscoIos Xe Version3.11.1e
CiscoIos Xe Version3.11.2ae
CiscoIos Xe Version3.11.2e
CiscoIos Xe Version3.11.3ae
CiscoIos Xe Version3.11.3e
CiscoIos Xe Version16.8.1
CiscoIos Xe Version16.8.1a
CiscoIos Xe Version16.8.1b
CiscoIos Xe Version16.8.1c
CiscoIos Xe Version16.8.1d
CiscoIos Xe Version16.8.1e
CiscoIos Xe Version16.8.1s
CiscoIos Xe Version16.8.2
CiscoIos Xe Version16.8.3
CiscoIos Xe Version16.9.1
CiscoIos Xe Version16.9.1a
CiscoIos Xe Version16.9.1b
CiscoIos Xe Version16.9.1c
CiscoIos Xe Version16.9.1d
CiscoIos Xe Version16.9.1s
CiscoIos Xe Version16.9.2
CiscoIos Xe Version16.9.2a
CiscoIos Xe Version16.9.2s
CiscoIos Xe Version16.9.3
CiscoIos Xe Version16.9.3a
CiscoIos Xe Version16.9.3h
CiscoIos Xe Version16.9.3s
CiscoIos Xe Version16.9.4
CiscoIos Xe Version16.9.4c
CiscoIos Xe Version16.9.5
CiscoIos Xe Version16.9.5f
CiscoIos Xe Version16.9.6
CiscoIos Xe Version16.10.1
CiscoIos Xe Version16.10.1a
CiscoIos Xe Version16.10.1b
CiscoIos Xe Version16.10.1c
CiscoIos Xe Version16.10.1d
CiscoIos Xe Version16.10.1e
CiscoIos Xe Version16.10.1f
CiscoIos Xe Version16.10.1g
CiscoIos Xe Version16.10.1s
CiscoIos Xe Version16.10.2
CiscoIos Xe Version16.10.3
CiscoIos Xe Version16.11.1
CiscoIos Xe Version16.11.1a
CiscoIos Xe Version16.11.1b
CiscoIos Xe Version16.11.1c
CiscoIos Xe Version16.11.1s
CiscoIos Xe Version16.11.2
CiscoIos Xe Version16.12.1
CiscoIos Xe Version16.12.1a
CiscoIos Xe Version16.12.1c
CiscoIos Xe Version16.12.1s
CiscoIos Xe Version16.12.1t
CiscoIos Xe Version16.12.1w
CiscoIos Xe Version16.12.1x
CiscoIos Xe Version16.12.1y
CiscoIos Xe Version16.12.1z
CiscoIos Xe Version16.12.1za
CiscoIos Xe Version16.12.2
CiscoIos Xe Version16.12.2a
CiscoIos Xe Version16.12.2s
CiscoIos Xe Version16.12.2t
CiscoIos Xe Version16.12.3
CiscoIos Xe Version16.12.3a
CiscoIos Xe Version16.12.3s
CiscoIos Xe Version17.1.1
CiscoIos Xe Version17.1.1a
CiscoIos Xe Version17.1.1s
CiscoIos Xe Version17.1.1t
CiscoIos Xe Version17.1.2
CiscoIos Xe Version17.2.1
CiscoIos Xe Version17.2.1a
CiscoIos Xe Version17.2.1r
CiscoIos Xe Version17.2.1v
CiscoIos Xe Version17.2.2
CiscoIos Xe Version17.2.3
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.04% 0.122
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 6.7 0.8 5.9
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 7.2 3.9 10
AV:L/AC:L/Au:N/C:C/I:C/A:C
psirt@cisco.com 5.1 0.8 4.2
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:H/A:N
CWE-489 Active Debug Code

The product is deployed to unauthorized actors with debugging code still enabled or active, which can create unintended entry points or expose sensitive information.