7.8
CVE-2021-1419
- EPSS 0.04%
- Veröffentlicht 23.09.2021 03:15:07
- Zuletzt bearbeitet 21.11.2024 05:44:19
- Quelle psirt@cisco.com
- Teams Watchlist Login
- Unerledigt Login
A vulnerability in the SSH management feature of multiple Cisco Access Points (APs) platforms could allow a local, authenticated user to modify files on the affected device and possibly gain escalated privileges. The vulnerability is due to improper checking on file operations within the SSH management interface. A network administrator user could exploit this vulnerability by accessing an affected device through SSH management to make a configuration change. A successful exploit could allow the attacker to gain privileges equivalent to the root user.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Cisco ≫ Aironet 1542d Firmware Version-
Cisco ≫ Aironet 1562d Firmware Version-
Cisco ≫ Aironet 1815m Firmware Version-
Cisco ≫ Aironet 1830e Firmware Version-
Cisco ≫ Aironet 1840i Firmware Version-
Cisco ≫ Aironet 1850e Firmware Version-
Cisco ≫ Aironet 2800i Firmware Version-
Cisco ≫ Aironet 3800p Firmware Version-
Cisco ≫ Aironet 4800 Firmware Version-
Cisco ≫ Catalyst 9105axi Firmware Version-
Cisco ≫ Catalyst 9115axe Firmware Version-
Cisco ≫ Catalyst 9117 Firmware Version-
Cisco ≫ Catalyst 9120axi Firmware Version-
Cisco ≫ Catalyst 9124axd Firmware Version-
Cisco ≫ Catalyst 9130axe Firmware Version-
Cisco ≫ Catalyst Iw6300 Ac Firmware Version-
Cisco ≫ Esw6300 Firmware Version-
Cisco ≫ 1100-8p Firmware Version-
Cisco ≫ 1120 Firmware Version-
Cisco ≫ 1160 Firmware Version-
Cisco ≫ Wireless Lan Controller Software Version >= 8.10 < 8.10.151.0
Cisco ≫ Catalyst 9800 Firmware Version >= 16.12 < 16.12.6
Cisco ≫ Catalyst 9800 Firmware Version >= 17.3 < 17.3.3
Cisco ≫ Catalyst 9800 Firmware Version17.4
Cisco ≫ Aironet 1542i Firmware Version-
Cisco ≫ Catalyst 9800 Firmware Version >= 16.12 < 16.12.6
Cisco ≫ Catalyst 9800 Firmware Version >= 17.3 < 17.3.3
Cisco ≫ Catalyst 9800 Firmware Version17.4
Cisco ≫ Catalyst 9800 Firmware Version >= 16.12 < 16.12.6
Cisco ≫ Catalyst 9800 Firmware Version >= 17.3 < 17.3.3
Cisco ≫ Catalyst 9800 Firmware Version17.4
Cisco ≫ Catalyst 9800 Firmware Version >= 16.12 < 16.12.6
Cisco ≫ Catalyst 9800 Firmware Version >= 17.3 < 17.3.3
Cisco ≫ Catalyst 9800 Firmware Version17.4
Cisco ≫ Aironet 1562e Firmware Version-
Cisco ≫ Aironet 1562i Firmware Version-
Cisco ≫ Aironet 1815w Firmware Version-
Cisco ≫ Aironet 1815t Firmware Version-
Cisco ≫ Aironet 1815i Firmware Version-
Cisco ≫ Aironet 1830i Firmware Version-
Cisco ≫ Aironet 1850i Firmware Version-
Cisco ≫ Aironet 2800e Firmware Version-
Cisco ≫ Aironet 3800i Firmware Version-
Cisco ≫ Aironet 3800e Firmware Version-
Cisco ≫ Catalyst 9105axw Firmware Version-
Cisco ≫ Catalyst 9115axi Firmware Version-
Cisco ≫ Catalyst 9120axp Firmware Version-
Cisco ≫ Catalyst 9120axe Firmware Version-
Cisco ≫ Catalyst 9124axi Firmware Version-
Cisco ≫ Catalyst 9130axi Firmware Version-
Cisco ≫ Catalyst Iw6300 Dc Firmware Version-
Cisco ≫ Catalyst Iw6300 Dcw Firmware Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Typ | Quelle | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.04% | 0.069 |
Quelle | Base Score | Exploit Score | Impact Score | Vector String |
---|---|---|---|---|
nvd@nist.gov | 7.8 | 1.8 | 5.9 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
nvd@nist.gov | 7.2 | 3.9 | 10 |
AV:L/AC:L/Au:N/C:C/I:C/A:C
|
psirt@cisco.com | 7.8 | 1.8 | 5.9 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
CWE-284 Improper Access Control
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.