CVE-2021-34746
published 2021-09-02CVE-2021-34746: A vulnerability in the TACACS+ authentication, authorization and accounting (AAA) feature of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow…
PriorityP278critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
17.66%
96.8th percentile
A vulnerability in the TACACS+ authentication, authorization and accounting (AAA) feature of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an unauthenticated, remote attacker to bypass authentication and log in to an affected device as an administrator. This vulnerability is due to incomplete validation of user-supplied input that is passed to an authentication script. An attacker could exploit this vulnerability by injecting parameters into an authentication request. A successful exploit could allow the attacker to bypass authentication and log in as an administrator to the affected device.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | cisco_enterprise_nfv_infrastructure_software | — | — |
| cisco | enterprise_nfv_infrastructure | — | — |
| cisco | enterprise_nfv_infrastructure_software | < 4.6.1 | 4.6.1 |
Detection & IOCsextracted from sources · hover to see the quote
- →The vulnerability is exploited by injecting parameters into a TACACS+ authentication request targeting Cisco NFVIS; monitor for anomalous or malformed TACACS+ AAA authentication requests containing unexpected parameter injections. ↗
- →The attack vector is network-based and unauthenticated; monitor for unexpected administrative logins to Cisco NFVIS devices, especially those authenticated via TACACS+ AAA, from remote/untrusted sources. ↗
- →The root cause is incomplete validation of user-supplied input passed to an authentication script in the TACACS+ AAA feature; audit NFVIS authentication scripts for unexpected or unsanitized input handling. ↗
- ·This vulnerability only affects Cisco NFVIS deployments where the TACACS+ AAA feature is enabled; if TACACS+ is not configured, the device is not vulnerable. ↗
- ·There are no workarounds available for this vulnerability; patching via Cisco software updates is the only remediation path. ↗
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
vendor_cisco9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco Enterprise NFV Infrastructure Software Authentication Bypass Vulnerability
vendor_cisco·2021-09-01·CVSS 9.8
CVE-2021-34746 [CRITICAL] CWE-289 Cisco Enterprise NFV Infrastructure Software Authentication Bypass Vulnerability
Cisco Enterprise NFV Infrastructure Software Authentication Bypass Vulnerability
A vulnerability in the TACACS+ authentication, authorization and accounting (AAA) feature of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an unauthenticated, remote attacker to bypass authentication and log in to an affected device as an administrator.
This vulnerability is due to incomplete validation of user-supplied input that is passed to an authentication script. An attacker could exploit this vulnerability by injecting parameters into an authentication request. A successful exploit could allow the attacker to bypass authentication and log in as an administrator to the affected device.
Cisco has released software updates that address this vulnerability. There are no workarounds that
Cisco
Cisco Enterprise NFV Infrastructure Software Authentication Bypass Vulnerability
vendor_cisco·CVSS 3.1
CVE-2021-34746 Cisco Enterprise NFV Infrastructure Software Authentication Bypass Vulnerability
CVE-2021-34746: Cisco Enterprise NFV Infrastructure Software Authentication Bypass Vulnerability
A vulnerability in the TACACS+ authentication, authorization and accounting (AAA) feature of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an unauthenticated, remote attacker to bypass authentication and log in to an affected device as an administrator. This vulnerability is due to incomplete validation of user-supplied input that is passed to an authentication script. An attacker could exploit this vulnerability by injecting parameters into an authentication request. A successful exploit could allow the attacker to bypass authentication and log in as an administrator to the affected device. Cisco has released software updates that address this vulnerability. There are no
CVS
GHSA
GHSA-hjrv-6xv3-c6x3: A vulnerability in the TACACS+ authentication, authorization and accounting (AAA) feature of Cisco Enterprise NFV Infrastructure Software (NFVIS) coul
ghsa_unreviewed·2022-05-24
CVE-2021-34746 [CRITICAL] CWE-287 GHSA-hjrv-6xv3-c6x3: A vulnerability in the TACACS+ authentication, authorization and accounting (AAA) feature of Cisco Enterprise NFV Infrastructure Software (NFVIS) coul
A vulnerability in the TACACS+ authentication, authorization and accounting (AAA) feature of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an unauthenticated, remote attacker to bypass authentication and log in to an affected device as an administrator. This vulnerability is due to incomplete validation of user-supplied input that is passed to an authentication script. An attacker could exploit this vulnerability by injecting parameters into an authentication request. A successful exploit could allow the attacker to bypass authentication and log in as an administrator to the affected device.
No detection rules found.
No public exploits indexed.
https://github.com/orangecertcc/security-research/security/advisories/GHSA-gqx8-c4xr-c664https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-nfvis-g2DMVVhhttps://github.com/orangecertcc/security-research/security/advisories/GHSA-gqx8-c4xr-c664https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-nfvis-g2DMVVh
2021-09-02
Published