CVE-2021-1264

Severity
8.8HIGH
EPSS
0.8%
top 26.28%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 20
Latest updateMay 24

Description

A vulnerability in the Command Runner tool of Cisco DNA Center could allow an authenticated, remote attacker to perform a command injection attack. The vulnerability is due to insufficient input validation by the Command Runner tool. An attacker could exploit this vulnerability by providing crafted input during command execution or via a crafted command runner API call. A successful exploit could allow the attacker to execute arbitrary CLI commands on devices managed by Cisco DNA Center.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:HExploitability: 3.1 | Impact: 5.8

Affected Packages2 packages

🔴Vulnerability Details

2
GHSA
GHSA-j5x7-4h7r-4q2r: A vulnerability in the Command Runner tool of Cisco DNA Center could allow an authenticated, remote attacker to perform a command injection attack2022-05-24
CVEList
Cisco DNA Center Command Runner Command Injection Vulnerability2021-01-20

📋Vendor Advisories

1
Cisco
Cisco DNA Center Command Runner Command Injection Vulnerability2021-01-20