CVE-2021-1392
published 2021-03-24CVE-2021-1392: A vulnerability in the CLI command permissions of Cisco IOS and Cisco IOS XE Software could allow an authenticated, local attacker to retrieve the password for…
PriorityP341high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.22%
12.5th percentile
A vulnerability in the CLI command permissions of Cisco IOS and Cisco IOS XE Software could allow an authenticated, local attacker to retrieve the password for Common Industrial Protocol (CIP) and then remotely configure the device as an administrative user. This vulnerability exists because incorrect permissions are associated with the show cip security CLI command. An attacker could exploit this vulnerability by issuing the command to retrieve the password for CIP on an affected device. A successful exploit could allow the attacker to reconfigure the device.
Affected
216 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | cisco_ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
vendor_cisco7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA ICS
Rockwell Automation Stratix Switches
cisa_ics·2021-04-20·CVSS 7.8
[HIGH] Rockwell Automation Stratix Switches
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Rockwell Automation Stratix Switches
Last RevisedApril 20, 2021
Alert CodeICSA-21-110-02
## 1. EXECUTIVE SUMMARY
- CVSS v3 7.8
- ATTENTION: Exploitable remotely/ Low attack complexity
- Vendor: Rockwell Automation
- Equipment: Stratix Switches
- Vulnerabilities: Insufficiently Protected Credentials, Insufficient Verification of Data Authenticity, Use of Out-of-Range Pointer Offset, Insertion of Sensitive Information Into Log File, Command Injection, Improper Input Validation
## 2. RISK EVALUATION
Successful exploitation of these vulnerabilities may result in denial-of-serv
Cisco
Cisco IOS and IOS XE Software Common Industrial Protocol Privilege Escalation Vulnerability
vendor_cisco·2021-03-24·CVSS 7.8
CVE-2021-1392 [HIGH] CWE-522 Cisco IOS and IOS XE Software Common Industrial Protocol Privilege Escalation Vulnerability
Cisco IOS and IOS XE Software Common Industrial Protocol Privilege Escalation Vulnerability
A vulnerability in the CLI command permissions of Cisco IOS and Cisco IOS XE Software could allow an authenticated, local attacker to retrieve the password for Common Industrial Protocol (CIP) and then remotely configure the device as an administrative user.
This vulnerability exists because incorrect permissions are associated with the show cip security CLI command. An attacker could exploit this vulnerability by issuing the command to retrieve the password for CIP on an affected device. A successful exploit could allow the attacker to reconfigure the device.
Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.
This advisor
Cisco
Cisco IOS and IOS XE Software Common Industrial Protocol Privilege Escalation Vulnerability
vendor_cisco·CVSS 3.1
CVE-2021-1392 Cisco IOS and IOS XE Software Common Industrial Protocol Privilege Escalation Vulnerability
CVE-2021-1392: Cisco IOS and IOS XE Software Common Industrial Protocol Privilege Escalation Vulnerability
A vulnerability in the CLI command permissions of Cisco IOS and Cisco IOS XE Software could allow an authenticated, local attacker to retrieve the password for Common Industrial Protocol (CIP) and then remotely configure the device as an administrative user. This vulnerability exists because incorrect permissions are associated with the show cip security CLI command. An attacker could exploit this vulnerability by issuing the command to retrieve the password for CIP on an affected device. A successful exploit could allow the attacker to reconfigure the device. Cisco has released software updates that address this vulnerability. There are no
CVSS: 3.1
CWE: CWE-522, CWE-522
Bug IDs: CSC
GHSA
GHSA-xjw8-2g7c-qm56: A vulnerability in the CLI command permissions of Cisco IOS and Cisco IOS XE Software could allow an authenticated, local attacker to retrieve the pas
ghsa_unreviewed·2022-05-24
CVE-2021-1392 [HIGH] CWE-522 GHSA-xjw8-2g7c-qm56: A vulnerability in the CLI command permissions of Cisco IOS and Cisco IOS XE Software could allow an authenticated, local attacker to retrieve the pas
A vulnerability in the CLI command permissions of Cisco IOS and Cisco IOS XE Software could allow an authenticated, local attacker to retrieve the password for Common Industrial Protocol (CIP) and then remotely configure the device as an administrative user. This vulnerability exists because incorrect permissions are associated with the show cip security CLI command. An attacker could exploit this vulnerability by issuing the command to retrieve the password for CIP on an affected device. A successful exploit could allow the attacker to reconfigure the device.
GHSA
XXE vulnerability on Launch import with externally-defined DTD file
ghsa·2021-06-28
CVE-2021-29620 [HIGH] CWE-611 XXE vulnerability on Launch import with externally-defined DTD file
XXE vulnerability on Launch import with externally-defined DTD file
### Impact
Starting from version 3.1.0 we introduced a new feature of JUnit XML launch import. Unfortunately XML parser was not configured properly to prevent XML external entity (XXE) attacks. This allows a user to import a specifically-crafted XML file which imports external Document Type Definition (DTD) file with external entities for extraction of secrets from Report Portal service-api module or server-side request forgery.
### Patches
Fixed with: https://github.com/reportportal/service-api/pull/1392
### Binaries
`docker pull reportportal/service-api:5.4.0`
https://github.com/reportportal/service-api/packages/846871?version=5.4.0
### For more information
If you have any questions or comments about this advisory em
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2021-03-24
Published