CVE-2021-1447Improper Privilege Management in Cisco Content Security Management Appliance

Severity
6.7MEDIUMNVD
EPSS
0.0%
top 93.84%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 6
Latest updateMay 24

Description

A vulnerability in the user account management system of Cisco AsyncOS for Cisco Content Security Management Appliance (SMA) could allow an authenticated, local attacker to elevate their privileges to root. This vulnerability is due to a procedural flaw in the password generation algorithm. An attacker could exploit this vulnerability by enabling specific Administrator-only features and connecting to the appliance through the CLI with elevated privileges. A successful exploit could allow the att

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:HExploitability: 0.8 | Impact: 5.9

Affected Packages2 packages

🔴Vulnerability Details

2
GHSA
GHSA-mvqh-q454-4f7x: A vulnerability in the user account management system of Cisco AsyncOS for Cisco Content Security Management Appliance (SMA) could allow an authentica2022-05-24
CVEList
Cisco Content Security Management Appliance Privilege Escalation Vulnerability2021-05-06

📋Vendor Advisories

1
Cisco
Cisco Content Security Management Appliance Privilege Escalation Vulnerability2021-05-05
CVE-2021-1447 — Improper Privilege Management in Cisco | cvebase