cbcvebase.
CVE-2021-1539
published 2021-06-04

CVE-2021-1539: Multiple vulnerabilities in the authorization process of Cisco ASR 5000 Series Software (StarOS) could allow an authenticated, remote attacker to bypass…

PriorityP355high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
1.09%
61.5th percentile
Multiple vulnerabilities in the authorization process of Cisco ASR 5000 Series Software (StarOS) could allow an authenticated, remote attacker to bypass authorization and execute a subset of CLI commands on an affected device. For more information about these vulnerabilities, see the Details section of this advisory.

Affected

8 ranges
VendorProductVersion rangeFixed in
ciscoasr_5000_series
ciscocisco_asr_5000_series_software
ciscostaros< 21.16.921.16.9
ciscostaros>= 21.17.0 < 21.17.1021.17.10
ciscostaros>= 21.18.0 < 21.18.1621.18.16
ciscostaros>= 21.19.0 < 21.19.1121.19.11
ciscostaros>= 21.19.n < 21.19.n721.19.n7
ciscostaros>= 21.20.0 < 21.20.821.20.8

CVSS provenance

nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.06.5MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
vendor_cisco8.1HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.