cbcvebase.
CVE-2021-1540
published 2021-06-04

CVE-2021-1540: Multiple vulnerabilities in the authorization process of Cisco ASR 5000 Series Software (StarOS) could allow an authenticated, remote attacker to bypass…

PriorityP344high7.2CVSS 3.1
AVNACLPRHUINSUCHIHAH
EPSS
1.05%
60.4th percentile
Multiple vulnerabilities in the authorization process of Cisco ASR 5000 Series Software (StarOS) could allow an authenticated, remote attacker to bypass authorization and execute a subset of CLI commands on an affected device. For more information about these vulnerabilities, see the Details section of this advisory.

Affected

8 ranges
VendorProductVersion rangeFixed in
ciscoasr_5000_series
ciscocisco_asr_5000_series_software
ciscostaros< 21.16.921.16.9
ciscostaros>= 21.17.0 < 21.17.1021.17.10
ciscostaros>= 21.18.0 < 21.18.1621.18.16
ciscostaros>= 21.19.0 < 21.19.1121.19.11
ciscostaros>= 21.19.n < 21.19.n721.19.n7
ciscostaros>= 21.20.0 < 21.20.821.20.8

CVSS provenance

nvdv3.17.2HIGHCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
nvdv2.06.0MEDIUMAV:N/AC:M/Au:S/C:P/I:P/A:P
vendor_cisco8.1HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.