CVE-2021-1306
published 2021-05-22CVE-2021-1306: A vulnerability in the restricted shell of Cisco Evolved Programmable Network (EPN) Manager, Cisco Identity Services Engine (ISE), and Cisco Prime…
PriorityP416low3.4CVSS 3.1
AVLACLPRHUINSUCLILAN
EPSS
0.21%
11.5th percentile
A vulnerability in the restricted shell of Cisco Evolved Programmable Network (EPN) Manager, Cisco Identity Services Engine (ISE), and Cisco Prime Infrastructure could allow an authenticated, local attacker to identify directories and write arbitrary files to the file system. This vulnerability is due to improper validation of parameters that are sent to a CLI command within the restricted shell. An attacker could exploit this vulnerability by logging in to the device and issuing certain CLI commands. A successful exploit could allow the attacker to identify file directories on the affected device and write arbitrary files to the file system on the affected device. To exploit this vulnerability, the attacker must be an authenticated shell user.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | ade-os_local_file_inclusion | — | — |
| cisco | cisco_identity_services_engine_software | — | — |
| cisco | evolved_programmable_network_manager | < 5.0.1 | 5.0.1 |
| cisco | identity_services_engine | < 2.7.0 | 2.7.0 |
| cisco | identity_services_engine | — | — |
| cisco | identity_services_engine | — | — |
| cisco | prime_infrastructure | < 3.8.1 | 3.8.1 |
| cisco | prime_infrastructure | — | — |
CVSS provenance
nvdv3.13.4LOWCVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N
nvdv2.03.6LOWAV:L/AC:L/Au:N/C:P/I:P/A:N
vendor_cisco4.4MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco ADE-OS Local File Inclusion Vulnerability
vendor_cisco·2021-05-19·CVSS 4.4
CVE-2021-1306 [MEDIUM] CWE-73 Cisco ADE-OS Local File Inclusion Vulnerability
Cisco ADE-OS Local File Inclusion Vulnerability
A vulnerability in the restricted shell of Cisco Evolved Programmable Network (EPN) Manager, Cisco Identity Services Engine (ISE), and Cisco Prime Infrastructure could allow an authenticated, local attacker to identify directories and write arbitrary files to the file system.
This vulnerability is due to improper validation of parameters that are sent to a CLI command within the restricted shell. An attacker could exploit this vulnerability by logging in to the device and issuing certain CLI commands. A successful exploit could allow the attacker to identify file directories on the affected device and write arbitrary files to the file system on the affected device. To exploit this vulnerability, the attacker must be an authenticated shell u
Cisco
Cisco ADE-OS Local File Inclusion Vulnerability
vendor_cisco·CVSS 3.1
CVE-2021-1306 Cisco ADE-OS Local File Inclusion Vulnerability
CVE-2021-1306: Cisco ADE-OS Local File Inclusion Vulnerability
A vulnerability in the restricted shell of Cisco Evolved Programmable Network (EPN) Manager, Cisco Identity Services Engine (ISE), and Cisco Prime Infrastructure could allow an authenticated, local attacker to identify directories and write arbitrary files to the file system. This vulnerability is due to improper validation of parameters that are sent to a CLI command within the restricted shell. An attacker could exploit this vulnerability by logging in to the device and issuing certain CLI commands. A successful exploit could allow the attacker to identify file directories on the affected device and write arbitrary files to the file system on the affected device. To exploit this vulnerability, the attacker must be an authenti
GHSA
GHSA-v764-45vr-f9mp: A vulnerability in the restricted shell of Cisco Evolved Programmable Network (EPN) Manager, Cisco Identity Services Engine (ISE), and Cisco Prime Inf
ghsa_unreviewed·2022-05-24
CVE-2021-1306 [LOW] CWE-610 GHSA-v764-45vr-f9mp: A vulnerability in the restricted shell of Cisco Evolved Programmable Network (EPN) Manager, Cisco Identity Services Engine (ISE), and Cisco Prime Inf
A vulnerability in the restricted shell of Cisco Evolved Programmable Network (EPN) Manager, Cisco Identity Services Engine (ISE), and Cisco Prime Infrastructure could allow an authenticated, local attacker to identify directories and write arbitrary files to the file system. This vulnerability is due to improper validation of parameters that are sent to a CLI command within the restricted shell. An attacker could exploit this vulnerability by logging in to the device and issuing certain CLI commands. A successful exploit could allow the attacker to identify file directories on the affected device and write arbitrary files to the file system on the affected device. To exploit this vulnerability, the attacker must be an authenticated shell user.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2021-05-22
Published