7.8

CVE-2021-1442

A vulnerability in a diagnostic command for the Plug-and-Play (PnP) subsystem of Cisco IOS XE Software could allow an authenticated, local attacker to elevate privileges to the level of an Administrator user (level 15) on an affected device. The vulnerability is due to insufficient protection of sensitive information. An attacker with low privileges could exploit this vulnerability by issuing the diagnostic CLI show pnp profile when a specific PnP listener is enabled on the device. A successful exploit could allow the attacker to obtain a privileged authentication token. This token can be used to send crafted PnP messages and execute privileged commands on the targeted system.

Data is provided by the National Vulnerability Database (NVD)
CiscoIos Xe Version3.6.3e
CiscoIos Xe Version3.6.4e
CiscoIos Xe Version3.6.5ae
CiscoIos Xe Version3.6.5be
CiscoIos Xe Version3.6.5e
CiscoIos Xe Version3.6.6e
CiscoIos Xe Version3.6.7ae
CiscoIos Xe Version3.6.7be
CiscoIos Xe Version3.6.7e
CiscoIos Xe Version3.6.8e
CiscoIos Xe Version3.6.9ae
CiscoIos Xe Version3.6.9e
CiscoIos Xe Version3.6.10e
CiscoIos Xe Version3.7.3e
CiscoIos Xe Version3.7.4e
CiscoIos Xe Version3.7.5e
CiscoIos Xe Version3.8.0e
CiscoIos Xe Version3.8.1e
CiscoIos Xe Version3.8.2e
CiscoIos Xe Version3.8.3e
CiscoIos Xe Version3.8.4e
CiscoIos Xe Version3.8.5ae
CiscoIos Xe Version3.8.5e
CiscoIos Xe Version3.8.6e
CiscoIos Xe Version3.8.7e
CiscoIos Xe Version3.8.8e
CiscoIos Xe Version3.8.9e
CiscoIos Xe Version3.8.10e
CiscoIos Xe Version3.9.0e
CiscoIos Xe Version3.9.1e
CiscoIos Xe Version3.9.2be
CiscoIos Xe Version3.9.2e
CiscoIos Xe Version3.10.0ce
CiscoIos Xe Version3.10.0e
CiscoIos Xe Version3.10.1ae
CiscoIos Xe Version3.10.1e
CiscoIos Xe Version3.10.1se
CiscoIos Xe Version3.10.2e
CiscoIos Xe Version3.10.3e
CiscoIos Xe Version3.11.0e
CiscoIos Xe Version3.11.1ae
CiscoIos Xe Version3.11.1e
CiscoIos Xe Version3.11.2ae
CiscoIos Xe Version3.11.2e
CiscoIos Xe Version3.13.8s
CiscoIos Xe Version3.13.9s
CiscoIos Xe Version3.13.10s
CiscoIos Xe Version3.16.0as
CiscoIos Xe Version3.16.0bs
CiscoIos Xe Version3.16.0cs
CiscoIos Xe Version3.16.0s
CiscoIos Xe Version3.16.1as
CiscoIos Xe Version3.16.1s
CiscoIos Xe Version3.16.2as
CiscoIos Xe Version3.16.2bs
CiscoIos Xe Version3.16.2s
CiscoIos Xe Version3.16.3as
CiscoIos Xe Version3.16.3s
CiscoIos Xe Version3.16.4as
CiscoIos Xe Version3.16.4bs
CiscoIos Xe Version3.16.4cs
CiscoIos Xe Version3.16.4ds
CiscoIos Xe Version3.16.4es
CiscoIos Xe Version3.16.4gs
CiscoIos Xe Version3.16.4s
CiscoIos Xe Version3.16.5as
CiscoIos Xe Version3.16.5bs
CiscoIos Xe Version3.16.5s
CiscoIos Xe Version3.16.6bs
CiscoIos Xe Version3.16.6s
CiscoIos Xe Version3.16.7as
CiscoIos Xe Version3.16.7bs
CiscoIos Xe Version3.16.7s
CiscoIos Xe Version3.16.8s
CiscoIos Xe Version3.16.9s
CiscoIos Xe Version3.16.10as
CiscoIos Xe Version3.16.10s
CiscoIos Xe Version3.17.0s
CiscoIos Xe Version3.17.1as
CiscoIos Xe Version3.17.1s
CiscoIos Xe Version3.17.2s
CiscoIos Xe Version3.17.3s
CiscoIos Xe Version3.17.4s
CiscoIos Xe Version3.18.0as
CiscoIos Xe Version3.18.0s
CiscoIos Xe Version3.18.0sp
CiscoIos Xe Version3.18.1asp
CiscoIos Xe Version3.18.1bsp
CiscoIos Xe Version3.18.1csp
CiscoIos Xe Version3.18.1gsp
CiscoIos Xe Version3.18.1hsp
CiscoIos Xe Version3.18.1isp
CiscoIos Xe Version3.18.1s
CiscoIos Xe Version3.18.1sp
CiscoIos Xe Version3.18.2asp
CiscoIos Xe Version3.18.2s
CiscoIos Xe Version3.18.2sp
CiscoIos Xe Version3.18.3asp
CiscoIos Xe Version3.18.3bsp
CiscoIos Xe Version3.18.3s
CiscoIos Xe Version3.18.3sp
CiscoIos Xe Version3.18.4s
CiscoIos Xe Version3.18.4sp
CiscoIos Xe Version3.18.5sp
CiscoIos Xe Version3.18.6sp
CiscoIos Xe Version3.18.7sp
CiscoIos Xe Version3.18.8asp
CiscoIos Xe Version3.18.8sp
CiscoIos Xe Version16.1.1
CiscoIos Xe Version16.1.2
CiscoIos Xe Version16.1.3
CiscoIos Xe Version16.2.1
CiscoIos Xe Version16.2.2
CiscoIos Xe Version16.3.1
CiscoIos Xe Version16.3.1a
CiscoIos Xe Version16.3.2
CiscoIos Xe Version16.3.3
CiscoIos Xe Version16.3.4
CiscoIos Xe Version16.3.5
CiscoIos Xe Version16.3.5b
CiscoIos Xe Version16.3.6
CiscoIos Xe Version16.3.7
CiscoIos Xe Version16.3.8
CiscoIos Xe Version16.3.9
CiscoIos Xe Version16.3.10
CiscoIos Xe Version16.3.11
CiscoIos Xe Version16.4.1
CiscoIos Xe Version16.4.2
CiscoIos Xe Version16.4.3
CiscoIos Xe Version16.5.1
CiscoIos Xe Version16.5.1a
CiscoIos Xe Version16.5.1b
CiscoIos Xe Version16.5.2
CiscoIos Xe Version16.5.3
CiscoIos Xe Version16.6.1
CiscoIos Xe Version16.6.2
CiscoIos Xe Version16.6.3
CiscoIos Xe Version16.6.4
CiscoIos Xe Version16.6.4a
CiscoIos Xe Version16.6.4s
CiscoIos Xe Version16.6.5
CiscoIos Xe Version16.6.5a
CiscoIos Xe Version16.6.5b
CiscoIos Xe Version16.6.6
CiscoIos Xe Version16.6.7
CiscoIos Xe Version16.6.7a
CiscoIos Xe Version16.6.8
CiscoIos Xe Version16.7.1
CiscoIos Xe Version16.7.1a
CiscoIos Xe Version16.7.1b
CiscoIos Xe Version16.7.2
CiscoIos Xe Version16.7.3
CiscoIos Xe Version16.7.4
CiscoIos Xe Version16.8.1
CiscoIos Xe Version16.8.1a
CiscoIos Xe Version16.8.1b
CiscoIos Xe Version16.8.1c
CiscoIos Xe Version16.8.1d
CiscoIos Xe Version16.8.1e
CiscoIos Xe Version16.8.1s
CiscoIos Xe Version16.8.2
CiscoIos Xe Version16.8.3
CiscoIos Xe Version16.9.1
CiscoIos Xe Version16.9.1a
CiscoIos Xe Version16.9.1b
CiscoIos Xe Version16.9.1c
CiscoIos Xe Version16.9.1d
CiscoIos Xe Version16.9.1s
CiscoIos Xe Version16.9.2
CiscoIos Xe Version16.9.2a
CiscoIos Xe Version16.9.2s
CiscoIos Xe Version16.9.3
CiscoIos Xe Version16.9.3a
CiscoIos Xe Version16.9.3h
CiscoIos Xe Version16.9.3s
CiscoIos Xe Version16.9.4
CiscoIos Xe Version16.9.4c
CiscoIos Xe Version16.9.5
CiscoIos Xe Version16.9.5f
CiscoIos Xe Version16.9.6
CiscoIos Xe Version16.10.1
CiscoIos Xe Version16.10.1a
CiscoIos Xe Version16.10.1b
CiscoIos Xe Version16.10.1c
CiscoIos Xe Version16.10.1d
CiscoIos Xe Version16.10.1e
CiscoIos Xe Version16.10.1f
CiscoIos Xe Version16.10.1g
CiscoIos Xe Version16.10.1s
CiscoIos Xe Version16.10.2
CiscoIos Xe Version16.10.3
CiscoIos Xe Version16.11.1
CiscoIos Xe Version16.11.1a
CiscoIos Xe Version16.11.1b
CiscoIos Xe Version16.11.1c
CiscoIos Xe Version16.11.1s
CiscoIos Xe Version16.11.2
CiscoIos Xe Version16.12.1
CiscoIos Xe Version16.12.1a
CiscoIos Xe Version16.12.1c
CiscoIos Xe Version16.12.1s
CiscoIos Xe Version16.12.1t
CiscoIos Xe Version16.12.1w
CiscoIos Xe Version16.12.1x
CiscoIos Xe Version16.12.1y
CiscoIos Xe Version16.12.1z
CiscoIos Xe Version16.12.2
CiscoIos Xe Version16.12.2a
CiscoIos Xe Version16.12.2s
CiscoIos Xe Version16.12.2t
CiscoIos Xe Version16.12.3
CiscoIos Xe Version16.12.3a
CiscoIos Xe Version16.12.3s
CiscoIos Xe Version16.12.4
CiscoIos Xe Version16.12.4a
CiscoIos Xe Version17.1.1
CiscoIos Xe Version17.1.1a
CiscoIos Xe Version17.1.1s
CiscoIos Xe Version17.1.1t
CiscoIos Xe Version17.1.2
CiscoIos Xe Version17.2.1
CiscoIos Xe Version17.2.1a
CiscoIos Xe Version17.2.1r
CiscoIos Xe Version17.2.1v
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.05% 0.151
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 6.9 3.4 10
AV:L/AC:M/Au:N/C:C/I:C/A:C
psirt@cisco.com 7 1 5.9
CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE-532 Insertion of Sensitive Information into Log File

The product writes sensitive information to a log file.