CVE-2021-1434Files or Directories Accessible to External Parties in Cisco IOS XE Software

Severity
6.0MEDIUMNVD
CNA4.4
EPSS
0.1%
top 82.94%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 24
Latest updateMay 24

Description

A vulnerability in the CLI of Cisco IOS XE SD-WAN Software could allow an authenticated, local attacker to overwrite arbitrary files in the underlying file system. This vulnerability is due to insufficient validation of the parameters of a specific CLI command. An attacker could exploit this vulnerability by issuing that command with specific parameters. A successful exploit could allow the attacker to overwrite the content of any arbitrary file that resides on the underlying host file system.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:HExploitability: 0.8 | Impact: 5.2

Affected Packages2 packages

NVDcisco/ios_xe27 versions+26

🔴Vulnerability Details

2
GHSA
GHSA-93v4-x3jr-8cfq: A vulnerability in the CLI of Cisco IOS XE SD-WAN Software could allow an authenticated, local attacker to overwrite arbitrary files in the underlying2022-05-24
CVEList
Cisco IOS XE SD-WAN Software Arbitrary File Corruption Vulnerability2021-03-24

📋Vendor Advisories

1
Cisco
Cisco IOS XE SD-WAN Software Arbitrary File Corruption Vulnerability2021-03-24

🕵️Threat Intelligence

2
Talos
Vulnerability Spotlight: Heap overflow in Sound Exchange libsox library2022-03-23
Talos
Vulnerability Spotlight: Heap overflow in Sound Exchange libsox library2022-03-23
CVE-2021-1434 — Cisco IOS XE Software vulnerability | cvebase