CVE-2021-1390
published 2021-03-24CVE-2021-1390: A vulnerability in one of the diagnostic test CLI commands of Cisco IOS XE Software could allow an authenticated, local attacker to execute arbitrary code on…
PriorityP434medium6.7CVSS 3.1
AVLACLPRHUINSUCHIHAH
EPSS
0.33%
25.0th percentile
A vulnerability in one of the diagnostic test CLI commands of Cisco IOS XE Software could allow an authenticated, local attacker to execute arbitrary code on an affected device. To exploit this vulnerability, the attacker would need to have valid user credentials at privilege level 15. This vulnerability exists because the affected software permits modification of the run-time memory of an affected device under specific circumstances. An attacker could exploit this vulnerability by authenticating to the affected device and issuing a specific diagnostic test command at the CLI. A successful exploit could trigger a logic error in the code that was designed to restrict run-time memory modifications. The attacker could take advantage of this logic error to overwrite system memory locations and execute arbitrary code on the underlying Linux operating system (OS) of the affected device.
Affected
76 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | cisco_ios_xe_software | — | — |
| cisco | ios_xe | — | — |
| cisco | ios_xe | — | — |
| cisco | ios_xe | — | — |
| cisco | ios_xe | — | — |
| cisco | ios_xe | — | — |
| cisco | ios_xe | — | — |
| cisco | ios_xe | — | — |
| cisco | ios_xe | — | — |
| cisco | ios_xe | — | — |
| cisco | ios_xe | — | — |
| cisco | ios_xe | — | — |
| cisco | ios_xe | — | — |
| cisco | ios_xe | — | — |
| cisco | ios_xe | — | — |
| cisco | ios_xe | — | — |
| cisco | ios_xe | — | — |
| cisco | ios_xe | — | — |
| cisco | ios_xe | — | — |
| cisco | ios_xe | — | — |
| cisco | ios_xe | — | — |
| cisco | ios_xe | — | — |
| cisco | ios_xe | — | — |
| cisco | ios_xe | — | — |
| cisco | ios_xe | — | — |
CVSS provenance
nvdv3.16.7MEDIUMCVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
cisa9.8CRITICAL
vendor_cisco5.1MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-587f-4vmq-c6m5: A vulnerability in one of the diagnostic test CLI commands of Cisco IOS XE Software could allow an authenticated, local attacker to execute arbitrary
ghsa_unreviewed·2022-05-24
CVE-2021-1390 [HIGH] CWE-123 GHSA-587f-4vmq-c6m5: A vulnerability in one of the diagnostic test CLI commands of Cisco IOS XE Software could allow an authenticated, local attacker to execute arbitrary
A vulnerability in one of the diagnostic test CLI commands of Cisco IOS XE Software could allow an authenticated, local attacker to execute arbitrary code on an affected device. To exploit this vulnerability, the attacker would need to have valid user credentials at privilege level 15. This vulnerability exists because the affected software permits modification of the run-time memory of an affected device under specific circumstances. An attacker could exploit this vulnerability by authenticating to the affected device and issuing a specific diagnostic test command at the CLI. A successful exploit could trigger a logic error in the code that was designed to restrict run-time memory modifications. The attacker could take advantage of this logic error to overwrite system memory locations and
CISA
Microsoft Open Management Infrastructure (OMI) Privilege Escalation Vulnerability
cisa·2021-11-03·CVSS 7.8
CVE-2021-38648 [HIGH] CWE-1390 Microsoft Open Management Infrastructure (OMI) Privilege Escalation Vulnerability
Vulnerability: Microsoft Open Management Infrastructure (OMI) Privilege Escalation Vulnerability
Affected: Microsoft Open Management Infrastructure (OMI)
Microsoft Open Management Infrastructure (OMI) within Azure VM Management Extensions contains an unspecified vulnerability allowing privilege escalation.
Required Action: Apply updates per vendor instructions.
Notes: https://nvd.nist.gov/vuln/detail/CVE-2021-38648
Remediation Due Date: 2021-11-17
CISA
Microsoft Open Management Infrastructure (OMI) Remote Code Execution Vulnerability
cisa·2021-11-03·CVSS 9.8
CVE-2021-38647 [CRITICAL] CWE-1390 Microsoft Open Management Infrastructure (OMI) Remote Code Execution Vulnerability
Vulnerability: Microsoft Open Management Infrastructure (OMI) Remote Code Execution Vulnerability
Affected: Microsoft Open Management Infrastructure (OMI)
Microsoft Open Management Infrastructure (OMI) within Azure VM Management Extensions contains an unspecified vulnerability allowing remote code execution.
Required Action: Apply updates per vendor instructions.
Notes: https://nvd.nist.gov/vuln/detail/CVE-2021-38647
Remediation Due Date: 2021-11-17
Cisco
Cisco IOS XE Software Local Privilege Escalation Vulnerability
vendor_cisco·2021-03-24·CVSS 5.1
CVE-2021-1390 [MEDIUM] CWE-123 Cisco IOS XE Software Local Privilege Escalation Vulnerability
Cisco IOS XE Software Local Privilege Escalation Vulnerability
A vulnerability in one of the diagnostic test CLI commands of Cisco IOS XE Software could allow an authenticated, local attacker to execute arbitrary code on an affected device. To exploit this vulnerability, the attacker would need to have valid user credentials at privilege level 15.
This vulnerability exists because the affected software permits modification of the run-time memory of an affected device under specific circumstances. An attacker could exploit this vulnerability by authenticating to the affected device and issuing a specific diagnostic test command at the CLI. A successful exploit could trigger a logic error in the code that was designed to restrict run-time memory modifications. The attacker could take advan
Cisco
Cisco IOS XE Software Local Privilege Escalation Vulnerability
vendor_cisco·CVSS 3.1
CVE-2021-1390 Cisco IOS XE Software Local Privilege Escalation Vulnerability
CVE-2021-1390: Cisco IOS XE Software Local Privilege Escalation Vulnerability
A vulnerability in one of the diagnostic test CLI commands of Cisco IOS XE Software could allow an authenticated, local attacker to execute arbitrary code on an affected device. To exploit this vulnerability, the attacker would need to have valid user credentials at privilege level 15. This vulnerability exists because the affected software permits modification of the run-time memory of an affected device under specific circumstances. An attacker could exploit this vulnerability by authenticating to the affected device and issuing a specific diagnostic test command at the CLI. A successful exploit could trigger a logic error in the code that was designed to restrict run-time memory modifications. The attacker cou
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2021-03-24
Published