cbcvebase.
CVE-2021-1298
published 2021-01-20

CVE-2021-1298: Multiple vulnerabilities in Cisco SD-WAN products could allow an authenticated attacker to perform command injection attacks against an affected device, which…

PriorityP359high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
2.37%
81.9th percentile
Multiple vulnerabilities in Cisco SD-WAN products could allow an authenticated attacker to perform command injection attacks against an affected device, which could allow the attacker to take certain actions with root privileges on the device. For more information about these vulnerabilities, see the Details section of this advisory.

Affected

9 ranges
VendorProductVersion rangeFixed in
ciscocisco_sd-wan_solution
ciscosd-wan
ciscosd-wan_firmware
ciscosd-wan_firmware
ciscosd-wan_firmware
ciscosd-wan_firmware
ciscosd-wan_firmware
ciscosd-wan_firmware
ciscosd-wan_firmware

CVSS provenance

nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv3.08.1HIGHCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
nvdv2.09.0CRITICALAV:N/AC:L/Au:S/C:C/I:C/A:C
vendor_cisco9.9CRITICAL
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.