cbcvebase.
CVE-2021-1359
published 2021-07-08

CVE-2021-1359: A vulnerability in the configuration management of Cisco AsyncOS for Cisco Web Security Appliance (WSA) could allow an authenticated, remote attacker to…

PriorityP263high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
1.88%
77.1th percentile
A vulnerability in the configuration management of Cisco AsyncOS for Cisco Web Security Appliance (WSA) could allow an authenticated, remote attacker to perform command injection and elevate privileges to root. This vulnerability is due to insufficient validation of user-supplied XML input for the web interface. An attacker could exploit this vulnerability by uploading crafted XML configuration files that contain scripting code to a vulnerable device. A successful exploit could allow the attacker to execute arbitrary commands on the underlying operating system and elevate privileges to root. An attacker would need a valid user account with the rights to upload configuration files to exploit this vulnerability.

Affected

6 ranges
VendorProductVersion rangeFixed in
ciscoasyncos>= 11.8.0 < 12.0.3-00512.0.3-005
ciscoasyncos>= 12.5.0 < 12.5.212.5.2
ciscocisco_web_security_appliance
ciscoweb_security_appliance
ciscoweb_security_appliance
ciscoweb_security_appliance

Detection & IOCsextracted from sources · hover to see the quote

  • Detect upload of crafted XML configuration files containing scripting/command injection code to the Cisco WSA web interface
  • Monitor for privilege escalation to root on Cisco WSA (AsyncOS) following XML configuration file uploads via the web interface
  • Audit user accounts with rights to upload configuration files on Cisco WSA for unauthorized or anomalous activity, as exploitation requires this privilege level
  • ·Exploitation requires an authenticated user account with configuration file upload rights; unauthenticated exploitation is not possible
  • ·No workarounds are available; remediation requires applying Cisco software updates
  • ·Vulnerability is tracked under Cisco Bug ID CSCvv81569 and affects Cisco AsyncOS for Cisco Web Security Appliance (WSA)

CVSS provenance

nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.09.0CRITICALAV:N/AC:L/Au:S/C:C/I:C/A:C
vendor_cisco6.3MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.