CVE-2021-1264
published 2021-01-20CVE-2021-1264: A vulnerability in the Command Runner tool of Cisco DNA Center could allow an authenticated, remote attacker to perform a command injection attack. The…
PriorityP263high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
3.72%
88.6th percentile
A vulnerability in the Command Runner tool of Cisco DNA Center could allow an authenticated, remote attacker to perform a command injection attack. The vulnerability is due to insufficient input validation by the Command Runner tool. An attacker could exploit this vulnerability by providing crafted input during command execution or via a crafted command runner API call. A successful exploit could allow the attacker to execute arbitrary CLI commands on devices managed by Cisco DNA Center.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | catalyst_center | < 1.3.1.0 | 1.3.1.0 |
| cisco | cisco_digital_network_architecture_center | — | — |
| cisco | dna_center | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Monitor for crafted input during Command Runner tool execution or via the Command Runner API call in Cisco DNA Center, which may indicate a command injection attempt (CWE-78). ↗
- →Audit and alert on unexpected or anomalous CLI commands executed on devices managed by Cisco DNA Center, as successful exploitation results in arbitrary CLI command execution on managed devices. ↗
- ·Exploitation requires the attacker to be authenticated; however, any authenticated remote user of Cisco DNA Center could leverage the Command Runner tool or API to perform command injection. ↗
- ·There are no workarounds available; patching via Cisco-released software updates is the only remediation. ↗
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.09.0CRITICALAV:N/AC:L/Au:S/C:C/I:C/A:C
vendor_cisco9.6CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco DNA Center Command Runner Command Injection Vulnerability
vendor_cisco·2021-01-20·CVSS 9.6
CVE-2021-1264 [CRITICAL] CWE-78 Cisco DNA Center Command Runner Command Injection Vulnerability
Cisco DNA Center Command Runner Command Injection Vulnerability
A vulnerability in the Command Runner tool of Cisco DNA Center could allow an authenticated, remote attacker to perform a command injection attack.
The vulnerability is due to insufficient input validation by the Command Runner tool. An attacker could exploit this vulnerability by providing crafted input during command execution or via a crafted command runner API call. A successful exploit could allow the attacker to execute arbitrary CLI commands on devices managed by Cisco DNA Center.
Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.
This advisory is available at the following link:https://sec.cloudapps.cisco.com/security/center/content/CiscoSecu
Cisco
Cisco DNA Center Command Runner Command Injection Vulnerability
vendor_cisco·CVSS 3.1
CVE-2021-1264 Cisco DNA Center Command Runner Command Injection Vulnerability
CVE-2021-1264: Cisco DNA Center Command Runner Command Injection Vulnerability
A vulnerability in the Command Runner tool of Cisco DNA Center could allow an authenticated, remote attacker to perform a command injection attack. The vulnerability is due to insufficient input validation by the Command Runner tool. An attacker could exploit this vulnerability by providing crafted input during command execution or via a crafted command runner API call. A successful exploit could allow the attacker to execute arbitrary CLI commands on devices managed by Cisco DNA Center. Cisco has released software updates that address this vulnerability. There are no
CVSS: 3.1
CWE: CWE-78, CWE-78
Bug IDs: CSCvq39748
GHSA
GHSA-j5x7-4h7r-4q2r: A vulnerability in the Command Runner tool of Cisco DNA Center could allow an authenticated, remote attacker to perform a command injection attack
ghsa_unreviewed·2022-05-24
CVE-2021-1264 [HIGH] CWE-78 GHSA-j5x7-4h7r-4q2r: A vulnerability in the Command Runner tool of Cisco DNA Center could allow an authenticated, remote attacker to perform a command injection attack
A vulnerability in the Command Runner tool of Cisco DNA Center could allow an authenticated, remote attacker to perform a command injection attack.
The vulnerability is due to insufficient input validation by the Command Runner tool. An attacker could exploit this vulnerability by providing crafted input during command execution or via a crafted command runner API call. A successful exploit could allow the attacker to execute arbitrary CLI commands on devices managed by Cisco DNA Center.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2021-01-20
Published