7.8

CVE-2021-1392

A vulnerability in the CLI command permissions of Cisco IOS and Cisco IOS XE Software could allow an authenticated, local attacker to retrieve the password for Common Industrial Protocol (CIP) and then remotely configure the device as an administrative user. This vulnerability exists because incorrect permissions are associated with the show cip security CLI command. An attacker could exploit this vulnerability by issuing the command to retrieve the password for CIP on an affected device. A successful exploit could allow the attacker to reconfigure the device.

Data is provided by the National Vulnerability Database (NVD)
CiscoIos Version15.0(1)ey
CiscoIos Version15.0(1)ey1
CiscoIos Version15.0(1)ey2
CiscoIos Version15.1(3)svs
CiscoIos Version15.1(3)svt1
CiscoIos Version15.2(1)ey
CiscoIos Version15.2(2)e
CiscoIos Version15.2(2)e1
CiscoIos Version15.2(2)e2
CiscoIos Version15.2(2)e3
CiscoIos Version15.2(2)e4
CiscoIos Version15.2(2)e5
CiscoIos Version15.2(2)e5a
CiscoIos Version15.2(2)e5b
CiscoIos Version15.2(2)e6
CiscoIos Version15.2(2)e7
CiscoIos Version15.2(2)e7b
CiscoIos Version15.2(2)e8
CiscoIos Version15.2(2)e9
CiscoIos Version15.2(2)e10
CiscoIos Version15.2(2)ea
CiscoIos Version15.2(2)ea1
CiscoIos Version15.2(2)ea2
CiscoIos Version15.2(2)ea3
CiscoIos Version15.2(2)eb
CiscoIos Version15.2(2)eb1
CiscoIos Version15.2(2)eb2
CiscoIos Version15.2(2a)e2
CiscoIos Version15.2(2b)e
CiscoIos Version15.2(3)e1
CiscoIos Version15.2(3)e2
CiscoIos Version15.2(3)e3
CiscoIos Version15.2(3)e4
CiscoIos Version15.2(3)e5
CiscoIos Version15.2(3)ea
CiscoIos Version15.2(4)e5a
CiscoIos Version15.2(4)ea
CiscoIos Version15.2(4)ea1
CiscoIos Version15.2(4)ea2
CiscoIos Version15.2(4)ea3
CiscoIos Version15.2(4)ea4
CiscoIos Version15.2(4)ea5
CiscoIos Version15.2(4)ea6
CiscoIos Version15.2(4)ea7
CiscoIos Version15.2(4)ea8
CiscoIos Version15.2(4)ea9
CiscoIos Version15.2(4)ea9a
CiscoIos Version15.2(4)ea10
CiscoIos Version15.2(4)ec1
CiscoIos Version15.2(4)ec2
CiscoIos Version15.2(4)jaz
CiscoIos Version15.2(5)e
CiscoIos Version15.2(5)e1
CiscoIos Version15.2(5)e2
CiscoIos Version15.2(5)e2b
CiscoIos Version15.2(5)e2c
CiscoIos Version15.2(5)ea
CiscoIos Version15.2(5a)e1
CiscoIos Version15.2(6)e
CiscoIos Version15.2(6)e0a
CiscoIos Version15.2(6)e0c
CiscoIos Version15.2(6)e1
CiscoIos Version15.2(6)e1a
CiscoIos Version15.2(6)e1s
CiscoIos Version15.2(7)e0b
CiscoIos Version15.2(7a)e0b
CiscoIos Version15.2(7b)e0b
CiscoIos Version15.3(3)ja1
CiscoIos Version15.3(3)ja4
CiscoIos Version15.3(3)ja5
CiscoIos Version15.3(3)ja6
CiscoIos Version15.3(3)ja7
CiscoIos Version15.3(3)ja8
CiscoIos Version15.3(3)ja10
CiscoIos Version15.3(3)ja11
CiscoIos Version15.3(3)ja12
CiscoIos Version15.3(3)jaa
CiscoIos Version15.3(3)jax
CiscoIos Version15.3(3)jax1
CiscoIos Version15.3(3)jax2
CiscoIos Version15.3(3)jb
CiscoIos Version15.3(3)jbb
CiscoIos Version15.3(3)jbb1
CiscoIos Version15.3(3)jbb2
CiscoIos Version15.3(3)jbb4
CiscoIos Version15.3(3)jbb5
CiscoIos Version15.3(3)jbb6
CiscoIos Version15.3(3)jbb6a
CiscoIos Version15.3(3)jbb8
CiscoIos Version15.3(3)jc
CiscoIos Version15.3(3)jc1
CiscoIos Version15.3(3)jc2
CiscoIos Version15.3(3)jc3
CiscoIos Version15.3(3)jc4
CiscoIos Version15.3(3)jc5
CiscoIos Version15.3(3)jc6
CiscoIos Version15.3(3)jc8
CiscoIos Version15.3(3)jc9
CiscoIos Version15.3(3)jc14
CiscoIos Version15.3(3)jd
CiscoIos Version15.3(3)jd2
CiscoIos Version15.3(3)jd3
CiscoIos Version15.3(3)jd4
CiscoIos Version15.3(3)jd5
CiscoIos Version15.3(3)jd6
CiscoIos Version15.3(3)jd7
CiscoIos Version15.3(3)jd8
CiscoIos Version15.3(3)jd9
CiscoIos Version15.3(3)jd11
CiscoIos Version15.3(3)jd12
CiscoIos Version15.3(3)jd13
CiscoIos Version15.3(3)jd14
CiscoIos Version15.3(3)jd16
CiscoIos Version15.3(3)jd17
CiscoIos Version15.3(3)je
CiscoIos Version15.3(3)jf
CiscoIos Version15.3(3)jf1
CiscoIos Version15.3(3)jf2
CiscoIos Version15.3(3)jf4
CiscoIos Version15.3(3)jf5
CiscoIos Version15.3(3)jf6
CiscoIos Version15.3(3)jf7
CiscoIos Version15.3(3)jf8
CiscoIos Version15.3(3)jf9
CiscoIos Version15.3(3)jf10
CiscoIos Version15.3(3)jf11
CiscoIos Version15.3(3)jf12
CiscoIos Version15.3(3)jf12i
CiscoIos Version15.3(3)jf13
CiscoIos Version15.3(3)jg
CiscoIos Version15.3(3)jg1
CiscoIos Version15.3(3)jh
CiscoIos Version15.3(3)jh1
CiscoIos Version15.3(3)ji1
CiscoIos Version15.3(3)ji3
CiscoIos Version15.3(3)ji4
CiscoIos Version15.3(3)ji5
CiscoIos Version15.3(3)ji6
CiscoIos Version15.3(3)jj
CiscoIos Version15.3(3)jj1
CiscoIos Version15.3(3)jk
CiscoIos Version15.3(3)jk1
CiscoIos Version15.3(3)jk1t
CiscoIos Version15.3(3)jk2
CiscoIos Version15.3(3)jk2a
CiscoIos Version15.3(3)jk3
CiscoIos Version15.3(3)jk4
CiscoIos Version15.3(3)jn
CiscoIos Version15.3(3)jn3
CiscoIos Version15.3(3)jn4
CiscoIos Version15.3(3)jn6
CiscoIos Version15.3(3)jn7
CiscoIos Version15.3(3)jn8
CiscoIos Version15.3(3)jn9
CiscoIos Version15.3(3)jn11
CiscoIos Version15.3(3)jn13
CiscoIos Version15.3(3)jn14
CiscoIos Version15.3(3)jn15
CiscoIos Version15.3(3)jnb
CiscoIos Version15.3(3)jnb1
CiscoIos Version15.3(3)jnb2
CiscoIos Version15.3(3)jnb3
CiscoIos Version15.3(3)jnb4
CiscoIos Version15.3(3)jnb5
CiscoIos Version15.3(3)jnb6
CiscoIos Version15.3(3)jnc
CiscoIos Version15.3(3)jnc1
CiscoIos Version15.3(3)jnc2
CiscoIos Version15.3(3)jnc3
CiscoIos Version15.3(3)jnc4
CiscoIos Version15.3(3)jnd
CiscoIos Version15.3(3)jnd1
CiscoIos Version15.3(3)jnd2
CiscoIos Version15.3(3)jnd3
CiscoIos Version15.3(3)jnp
CiscoIos Version15.3(3)jnp1
CiscoIos Version15.3(3)jnp3
CiscoIos Version15.3(3)jpb
CiscoIos Version15.3(3)jpb1
CiscoIos Version15.3(3)jpc
CiscoIos Version15.3(3)jpc1
CiscoIos Version15.3(3)jpc2
CiscoIos Version15.3(3)jpc3
CiscoIos Version15.3(3)jpc5
CiscoIos Version15.3(3)jpd
CiscoIos Xe Version3.3.0xo
CiscoIos Xe Version3.3.1xo
CiscoIos Xe Version3.3.2xo
CiscoIos Xe Version3.6.5be
CiscoIos Xe Version3.7.4e
CiscoIos Xe Version3.7.5e
CiscoIos Xe Version16.9.1
CiscoIos Xe Version16.9.1d
CiscoIos Xe Version16.10.1
CiscoIos Xe Version16.10.1e
CiscoIos Xe Version16.11.1
CiscoIos Xe Version16.11.1a
CiscoIos Xe Version16.11.1c
CiscoIos Xe Version16.11.1s
CiscoIos Xe Version16.11.2
CiscoIos Xe Version16.12.1
CiscoIos Xe Version16.12.1c
CiscoIos Xe Version16.12.1s
CiscoIos Xe Version16.12.2
CiscoIos Xe Version16.12.2s
CiscoIos Xe Version16.12.2t
CiscoIos Xe Version16.12.3
CiscoIos Xe Version16.12.3s
CiscoIos Xe Version16.12.4
CiscoIos Xe Version17.1.1
CiscoIos Xe Version17.1.1s
CiscoIos Xe Version17.1.1t
CiscoIos Xe Version17.1.2
CiscoIos Xe Version17.2.1
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.03% 0.075
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 2.1 3.9 2.9
AV:L/AC:L/Au:N/C:P/I:N/A:N
psirt@cisco.com 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE-522 Insufficiently Protected Credentials

The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.