CVE-2021-1584

Severity
6.7MEDIUM
EPSS
0.1%
top 70.57%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 25
Latest updateMay 24

Description

A vulnerability in Cisco Nexus 9000 Series Fabric Switches in Application Centric Infrastructure (ACI) mode could allow an authenticated, local attacker to elevate privileges on an affected device. This vulnerability is due to insufficient restrictions during the execution of a specific CLI command. An attacker with administrative privileges could exploit this vulnerability by performing a command injection attack on the vulnerable command. A successful exploit could allow the attacker to access

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:NExploitability: 0.8 | Impact: 5.2

Affected Packages2 packages

Patches

🔴Vulnerability Details

2
GHSA
GHSA-82j7-7f93-vq2v: A vulnerability in Cisco Nexus 9000 Series Fabric Switches in Application Centric Infrastructure (ACI) mode could allow an authenticated, local attack2022-05-24
CVEList
Cisco Nexus 9000 Series Fabric Switches ACI Mode Privilege Escalation Vulnerability2021-08-25

📋Vendor Advisories

1
Cisco
Cisco Nexus 9000 Series Fabric Switches ACI Mode Privilege Escalation Vulnerability2021-08-25
CVE-2021-1584 (MEDIUM CVSS 6.7) | A vulnerability in Cisco Nexus 9000 | cvebase.io