7.8

CVE-2021-1419

A vulnerability in the SSH management feature of multiple Cisco Access Points (APs) platforms could allow a local, authenticated user to modify files on the affected device and possibly gain escalated privileges. The vulnerability is due to improper checking on file operations within the SSH management interface. A network administrator user could exploit this vulnerability by accessing an affected device through SSH management to make a configuration change. A successful exploit could allow the attacker to gain privileges equivalent to the root user.

Data is provided by the National Vulnerability Database (NVD)
CiscoAironet 1542d Firmware Version-
   CiscoAironet 1542d Version-
CiscoAironet 1562d Firmware Version-
   CiscoAironet 1562d Version-
CiscoAironet 1815m Firmware Version-
   CiscoAironet 1815m Version-
CiscoAironet 1830e Firmware Version-
   CiscoAironet 1830e Version-
CiscoAironet 1840i Firmware Version-
   CiscoAironet 1840i Version-
CiscoAironet 1850e Firmware Version-
   CiscoAironet 1850e Version-
CiscoAironet 2800i Firmware Version-
   CiscoAironet 2800i Version-
CiscoAironet 3800p Firmware Version-
   CiscoAironet 3800p Version-
CiscoAironet 4800 Firmware Version-
   CiscoAironet 4800 Version-
CiscoCatalyst 9105axi Firmware Version-
   CiscoCatalyst 9105axi Version-
CiscoCatalyst 9115axe Firmware Version-
   CiscoCatalyst 9115axe Version-
CiscoCatalyst 9117 Firmware Version-
   CiscoCatalyst 9117axi Version-
CiscoCatalyst 9120axi Firmware Version-
   CiscoCatalyst 9120axi Version-
CiscoCatalyst 9124axd Firmware Version-
   CiscoCatalyst 9124axd Version-
CiscoCatalyst 9130axe Firmware Version-
   CiscoCatalyst 9130axe Version-
CiscoCatalyst Iw6300 Ac Firmware Version-
   CiscoCatalyst Iw6300 Ac Version-
CiscoEsw6300 Firmware Version-
   CiscoEsw6300 Version-
Cisco1100-8p Firmware Version-
   Cisco1100-8p Version-
Cisco1120 Firmware Version-
   Cisco1120 Version-
Cisco1160 Firmware Version-
CiscoWireless Lan Controller Software Version >= 8.10 < 8.10.151.0
CiscoCatalyst 9800 Firmware Version >= 16.12 < 16.12.6
   CiscoCatalyst 9800-l Version-
CiscoCatalyst 9800 Firmware Version >= 17.3 < 17.3.3
   CiscoCatalyst 9800-l Version-
CiscoCatalyst 9800 Firmware Version17.4
   CiscoCatalyst 9800-l Version-
CiscoAironet 1542i Firmware Version-
   CiscoAironet 1542i Version-
CiscoCatalyst 9800 Firmware Version >= 16.12 < 16.12.6
   CiscoCatalyst 9800-cl Version-
CiscoCatalyst 9800 Firmware Version >= 17.3 < 17.3.3
   CiscoCatalyst 9800-cl Version-
CiscoCatalyst 9800 Firmware Version17.4
   CiscoCatalyst 9800-cl Version-
CiscoCatalyst 9800 Firmware Version >= 16.12 < 16.12.6
   CiscoCatalyst 9800-40 Version-
CiscoCatalyst 9800 Firmware Version >= 17.3 < 17.3.3
   CiscoCatalyst 9800-40 Version-
CiscoCatalyst 9800 Firmware Version17.4
   CiscoCatalyst 9800-40 Version-
CiscoCatalyst 9800 Firmware Version >= 16.12 < 16.12.6
   CiscoCatalyst 9800-80 Version-
CiscoCatalyst 9800 Firmware Version >= 17.3 < 17.3.3
   CiscoCatalyst 9800-80 Version-
CiscoCatalyst 9800 Firmware Version17.4
   CiscoCatalyst 9800-80 Version-
CiscoAironet 1562e Firmware Version-
   CiscoAironet 1562e Version-
CiscoAironet 1562i Firmware Version-
   CiscoAironet 1562i Version-
CiscoAironet 1815w Firmware Version-
   CiscoAironet 1815w Version-
CiscoAironet 1815t Firmware Version-
   CiscoAironet 1815t Version-
CiscoAironet 1815i Firmware Version-
   CiscoAironet 1815i Version-
CiscoAironet 1830i Firmware Version-
   CiscoAironet 1830i Version-
CiscoAironet 1850i Firmware Version-
   CiscoAironet 1850i Version-
CiscoAironet 2800e Firmware Version-
   CiscoAironet 2800e Version-
CiscoAironet 3800i Firmware Version-
   CiscoAironet 3800i Version-
CiscoAironet 3800e Firmware Version-
   CiscoAironet 3800e Version-
CiscoCatalyst 9105axw Firmware Version-
   CiscoCatalyst 9105axw Version-
CiscoCatalyst 9115axi Firmware Version-
   CiscoCatalyst 9115axi Version-
CiscoCatalyst 9120axp Firmware Version-
   CiscoCatalyst 9120axp Version-
CiscoCatalyst 9120axe Firmware Version-
   CiscoCatalyst 9120axe Version-
CiscoCatalyst 9124axi Firmware Version-
   CiscoCatalyst 9124axi Version-
CiscoCatalyst 9130axi Firmware Version-
   CiscoCatalyst 9130axi Version-
CiscoCatalyst Iw6300 Dc Firmware Version-
   CiscoCatalyst Iw6300 Dc Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.04% 0.069
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 7.2 3.9 10
AV:L/AC:L/Au:N/C:C/I:C/A:C
psirt@cisco.com 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE-284 Improper Access Control

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.