CVE-2021-1359

CWE-112CWE-744 documents4 sources
Severity
8.8HIGH
EPSS
1.2%
top 21.27%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 8
Latest updateMay 24

Description

A vulnerability in the configuration management of Cisco AsyncOS for Cisco Web Security Appliance (WSA) could allow an authenticated, remote attacker to perform command injection and elevate privileges to root. This vulnerability is due to insufficient validation of user-supplied XML input for the web interface. An attacker could exploit this vulnerability by uploading crafted XML configuration files that contain scripting code to a vulnerable device. A successful exploit could allow the attacke

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:LExploitability: 2.8 | Impact: 3.4

Affected Packages3 packages

NVDcisco/web_security_appliance11.8.0-429, 11.8.0-453+1
NVDcisco/asyncos11.8.012.0.3-005+1

🔴Vulnerability Details

2
GHSA
GHSA-9x2v-q9rg-r4cc: A vulnerability in the configuration management of Cisco AsyncOS for Cisco Web Security Appliance (WSA) could allow an authenticated, remote attacker2022-05-24
CVEList
Cisco Web Security Appliance Privilege Escalation Vulnerability2021-07-08

📋Vendor Advisories

1
Cisco
Cisco Web Security Appliance Privilege Escalation Vulnerability2021-07-07
CVE-2021-1359 (HIGH CVSS 8.8) | A vulnerability in the configuratio | cvebase.io