Lucene search

K
ciscoCiscoCISCO-SA-XE-SAP-OPLBZE68
HistoryMar 24, 2021 - 4:00 p.m.

Cisco IOS and IOS XE Software Common Industrial Protocol Privilege Escalation Vulnerability

2021-03-2416:00:00
tools.cisco.com
110
cisco
ios
ios xe
common industrial protocol
privilege escalation
vulnerability
cli command
permissions
cip
software updates

EPSS

0

Percentile

5.1%

A vulnerability in the CLI command permissions of Cisco IOS and Cisco IOS XE Software could allow an authenticated, local attacker to retrieve the password for Common Industrial Protocol (CIP) and then remotely configure the device as an administrative user.

This vulnerability exists because incorrect permissions are associated with the show cip security CLI command. An attacker could exploit this vulnerability by issuing the command to retrieve the password for CIP on an affected device. A successful exploit could allow the attacker to reconfigure the device.

Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.

This advisory is available at the following link:
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-XE-SAP-OPLbze68 [“https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-XE-SAP-OPLbze68”]

This advisory is part of the March 2021 release of the Cisco IOS and IOS XE Software Security Advisory Bundled Publication. For a complete list of the advisories and links to them, see Cisco Event Response: March 2021 Semiannual Cisco IOS and IOS XE Software Security Advisory Bundled Publication [“https://sec.cloudapps.cisco.com/security/center/viewErp.x?alertId=ERP-74408”].

Affected configurations

Vulners
Node
ciscoiosMatch15.0ey
OR
ciscoiosMatch15.0ea
OR
ciscoiosMatch15.2e
OR
ciscoiosMatch15.2ey
OR
ciscoiosMatch15.2jaz
OR
ciscoiosMatch15.2eb
OR
ciscoiosMatch15.2ea
OR
ciscoiosMatch15.3jn
OR
ciscoiosMatch15.3ja
OR
ciscoiosMatch15.3jaa
OR
ciscoiosMatch15.3jb
OR
ciscoiosMatch15.3jnb
OR
ciscoiosMatch15.3jax
OR
ciscoiosMatch15.3jbb
OR
ciscoiosMatch15.3jc
OR
ciscoiosMatch15.3jnc
OR
ciscoiosMatch15.3jnp
OR
ciscoiosMatch15.3jpb
OR
ciscoiosMatch15.3jd
OR
ciscoiosMatch15.2ec
OR
ciscoiosMatch15.3jpc
OR
ciscoiosMatch15.3jnd
OR
ciscoiosMatch15.3je
OR
ciscoiosMatch15.3jpd
OR
ciscoiosMatch15.3jf
OR
ciscoiosMatch15.3jg
OR
ciscoiosMatch15.3jh
OR
ciscoiosMatch15.3ji
OR
ciscoiosMatch15.3jk
OR
ciscoiosMatch15.3jj
OR
ciscoiosMatch15.3jpj
OR
ciscoiosMatch15.1svs
OR
ciscoiosMatch15.1svt
OR
ciscoiosMatch15.3jpr
OR
ciscocisco_ios_xe_softwareMatch3.6e
OR
ciscocisco_ios_xe_softwareMatch3.7e
OR
ciscocisco_ios_xe_softwareMatch16.9
OR
ciscocisco_ios_xe_softwareMatch16.10
OR
ciscocisco_ios_xe_softwareMatch16.11
OR
ciscocisco_ios_xe_softwareMatch16.12
OR
ciscocisco_ios_xe_softwareMatch17.1
OR
ciscocisco_ios_xe_softwareMatch17.2
OR
ciscoiosMatch15.0\(1\)ey
OR
ciscoiosMatch15.0\(1\)ey1
OR
ciscoiosMatch15.0\(1\)ey2
OR
ciscoiosMatch15.0\(2\)ea
OR
ciscoiosMatch15.0\(2\)ea1
OR
ciscoiosMatch15.2\(2\)e
OR
ciscoiosMatch15.2\(2\)e1
OR
ciscoiosMatch15.2\(2b\)e
OR
ciscoiosMatch15.2\(3\)e1
OR
ciscoiosMatch15.2\(2\)e2
OR
ciscoiosMatch15.2\(2\)e3
OR
ciscoiosMatch15.2\(2a\)e2
OR
ciscoiosMatch15.2\(3\)e2
OR
ciscoiosMatch15.2\(3\)e3
OR
ciscoiosMatch15.2\(2\)e4
OR
ciscoiosMatch15.2\(2\)e5
OR
ciscoiosMatch15.2\(3\)e4
OR
ciscoiosMatch15.2\(5\)e
OR
ciscoiosMatch15.2\(2\)e6
OR
ciscoiosMatch15.2\(5\)e1
OR
ciscoiosMatch15.2\(2\)e5a
OR
ciscoiosMatch15.2\(2\)e5b
OR
ciscoiosMatch15.2\(5a\)e1
OR
ciscoiosMatch15.2\(2\)e7
OR
ciscoiosMatch15.2\(5\)e2
OR
ciscoiosMatch15.2\(6\)e
OR
ciscoiosMatch15.2\(5\)e2c
OR
ciscoiosMatch15.2\(2\)e8
OR
ciscoiosMatch15.2\(6\)e0a
OR
ciscoiosMatch15.2\(6\)e1
OR
ciscoiosMatch15.2\(6\)e0c
OR
ciscoiosMatch15.2\(2\)e9
OR
ciscoiosMatch15.2\(6\)e1a
OR
ciscoiosMatch15.2\(6\)e1s
OR
ciscoiosMatch15.2\(2\)e10
OR
ciscoiosMatch15.2\(7\)e0b
OR
ciscoiosMatch15.2\(7a\)e0b
OR
ciscoiosMatch15.2\(7b\)e0b
OR
ciscoiosMatch15.2\(4\)e10e
OR
ciscoiosMatch15.2\(1\)ey
OR
ciscoiosMatch15.2\(4\)jaz
OR
ciscoiosMatch15.2\(2\)eb
OR
ciscoiosMatch15.2\(2\)eb1
OR
ciscoiosMatch15.2\(2\)eb2
OR
ciscoiosMatch15.2\(2\)ea
OR
ciscoiosMatch15.2\(2\)ea1
OR
ciscoiosMatch15.2\(2\)ea2
OR
ciscoiosMatch15.2\(3\)ea
OR
ciscoiosMatch15.2\(4\)ea
OR
ciscoiosMatch15.2\(4\)ea1
OR
ciscoiosMatch15.2\(2\)ea3
OR
ciscoiosMatch15.2\(4\)ea3
OR
ciscoiosMatch15.2\(5\)ea
OR
ciscoiosMatch15.2\(4\)ea4
OR
ciscoiosMatch15.2\(4\)ea2
OR
ciscoiosMatch15.2\(4\)ea5
OR
ciscoiosMatch15.2\(4\)ea6
OR
ciscoiosMatch15.2\(4\)ea7
OR
ciscoiosMatch15.2\(4\)ea8
OR
ciscoiosMatch15.2\(4\)ea9
OR
ciscoiosMatch15.2\(4\)ea9a
OR
ciscoiosMatch15.2\(4\)ea10
OR
ciscoiosMatch15.3\(3\)jn
OR
ciscoiosMatch15.3\(3\)jn3
OR
ciscoiosMatch15.3\(3\)jn4
OR
ciscoiosMatch15.3\(3\)jn6
OR
ciscoiosMatch15.3\(3\)jn7
OR
ciscoiosMatch15.3\(3\)jn8
OR
ciscoiosMatch15.3\(3\)jn9
OR
ciscoiosMatch15.3\(3\)jn11
OR
ciscoiosMatch15.3\(3\)jn13
OR
ciscoiosMatch15.3\(3\)jn14
OR
ciscoiosMatch15.3\(3\)jn15
OR
ciscoiosMatch15.3\(3\)ja1
OR
ciscoiosMatch15.3\(3\)ja4
OR
ciscoiosMatch15.3\(3\)ja5
OR
ciscoiosMatch15.3\(3\)ja6
OR
ciscoiosMatch15.3\(3\)ja7
OR
ciscoiosMatch15.3\(3\)ja8
OR
ciscoiosMatch15.3\(3\)ja10
OR
ciscoiosMatch15.3\(3\)ja11
OR
ciscoiosMatch15.3\(3\)ja12
OR
ciscoiosMatch15.3\(3\)jaa
OR
ciscoiosMatch15.3\(3\)jb
OR
ciscoiosMatch15.3\(3\)jnb
OR
ciscoiosMatch15.3\(3\)jnb1
OR
ciscoiosMatch15.3\(3\)jnb2
OR
ciscoiosMatch15.3\(3\)jnb3
OR
ciscoiosMatch15.3\(3\)jnb4
OR
ciscoiosMatch15.3\(3\)jnb6
OR
ciscoiosMatch15.3\(3\)jnb5
OR
ciscoiosMatch15.3\(3\)jax
OR
ciscoiosMatch15.3\(3\)jax1
OR
ciscoiosMatch15.3\(3\)jax2
OR
ciscoiosMatch15.3\(3\)jbb
OR
ciscoiosMatch15.3\(3\)jbb1
OR
ciscoiosMatch15.3\(3\)jbb2
OR
ciscoiosMatch15.3\(3\)jbb4
OR
ciscoiosMatch15.3\(3\)jbb5
OR
ciscoiosMatch15.3\(3\)jbb6
OR
ciscoiosMatch15.3\(3\)jbb8
OR
ciscoiosMatch15.3\(3\)jbb6a
OR
ciscoiosMatch15.3\(3\)jc
OR
ciscoiosMatch15.3\(3\)jc1
OR
ciscoiosMatch15.3\(3\)jc2
OR
ciscoiosMatch15.3\(3\)jc3
OR
ciscoiosMatch15.3\(3\)jc4
OR
ciscoiosMatch15.3\(3\)jc5
OR
ciscoiosMatch15.3\(3\)jc6
OR
ciscoiosMatch15.3\(3\)jc8
OR
ciscoiosMatch15.3\(3\)jc9
OR
ciscoiosMatch15.3\(3\)jc14
OR
ciscoiosMatch15.3\(3\)jnc
OR
ciscoiosMatch15.3\(3\)jnc1
OR
ciscoiosMatch15.3\(3\)jnc2
OR
ciscoiosMatch15.3\(3\)jnc3
OR
ciscoiosMatch15.3\(3\)jnc4
OR
ciscoiosMatch15.3\(3\)jnp
OR
ciscoiosMatch15.3\(3\)jnp1
OR
ciscoiosMatch15.3\(3\)jnp3
OR
ciscoiosMatch15.3\(3\)jpb
OR
ciscoiosMatch15.3\(3\)jpb1
OR
ciscoiosMatch15.3\(3\)jd
OR
ciscoiosMatch15.3\(3\)jd2
OR
ciscoiosMatch15.3\(3\)jd3
OR
ciscoiosMatch15.3\(3\)jd4
OR
ciscoiosMatch15.3\(3\)jd5
OR
ciscoiosMatch15.3\(3\)jd6
OR
ciscoiosMatch15.3\(3\)jd7
OR
ciscoiosMatch15.3\(3\)jd8
OR
ciscoiosMatch15.3\(3\)jd9
OR
ciscoiosMatch15.3\(3\)jd11
OR
ciscoiosMatch15.3\(3\)jd12
OR
ciscoiosMatch15.3\(3\)jd13
OR
ciscoiosMatch15.3\(3\)jd14
OR
ciscoiosMatch15.3\(3\)jd16
OR
ciscoiosMatch15.3\(3\)jd17
OR
ciscoiosMatch15.2\(4\)ec1
OR
ciscoiosMatch15.2\(4\)ec2
OR
ciscoiosMatch15.3\(3\)jpc
OR
ciscoiosMatch15.3\(3\)jpc1
OR
ciscoiosMatch15.3\(3\)jpc2
OR
ciscoiosMatch15.3\(3\)jpc3
OR
ciscoiosMatch15.3\(3\)jpc5
OR
ciscoiosMatch15.3\(3\)jnd
OR
ciscoiosMatch15.3\(3\)jnd1
OR
ciscoiosMatch15.3\(3\)jnd2
OR
ciscoiosMatch15.3\(3\)jnd3
OR
ciscoiosMatch15.3\(3\)je
OR
ciscoiosMatch15.3\(3\)jpd
OR
ciscoiosMatch15.3\(3\)jf
OR
ciscoiosMatch15.3\(3\)jf1
OR
ciscoiosMatch15.3\(3\)jf2
OR
ciscoiosMatch15.3\(3\)jf4
OR
ciscoiosMatch15.3\(3\)jf5
OR
ciscoiosMatch15.3\(3\)jf6
OR
ciscoiosMatch15.3\(3\)jf7
OR
ciscoiosMatch15.3\(3\)jf8
OR
ciscoiosMatch15.3\(3\)jf9
OR
ciscoiosMatch15.3\(3\)jf10
OR
ciscoiosMatch15.3\(3\)jf11
OR
ciscoiosMatch15.3\(3\)jf12
OR
ciscoiosMatch15.3\(3\)jf13
OR
ciscoiosMatch15.3\(3\)jf12i
OR
ciscoiosMatch15.3\(3\)jg
OR
ciscoiosMatch15.3\(3\)jg1
OR
ciscoiosMatch15.3\(3\)jh
OR
ciscoiosMatch15.3\(3\)jh1
OR
ciscoiosMatch15.3\(3\)ji1
OR
ciscoiosMatch15.3\(3\)ji3
OR
ciscoiosMatch15.3\(3\)ji4
OR
ciscoiosMatch15.3\(3\)ji5
OR
ciscoiosMatch15.3\(3\)ji6
OR
ciscoiosMatch15.3\(3\)jk
OR
ciscoiosMatch15.3\(3\)jk1
OR
ciscoiosMatch15.3\(3\)jk2
OR
ciscoiosMatch15.3\(3\)jk3
OR
ciscoiosMatch15.3\(3\)jk2a
OR
ciscoiosMatch15.3\(3\)jk1t
OR
ciscoiosMatch15.3\(3\)jk4
OR
ciscoiosMatch15.3\(3\)jj
OR
ciscoiosMatch15.3\(3\)jj1
OR
ciscoiosMatch15.3\(3\)jpj
OR
ciscoiosMatch15.1\(3\)svs
OR
ciscoiosMatch15.1\(3\)svt1
OR
ciscoiosMatch15.3\(3\)jpr1
OR
ciscocisco_ios_xe_softwareMatch3.6.5be
OR
ciscocisco_ios_xe_softwareMatch3.7.4e
OR
ciscocisco_ios_xe_softwareMatch3.7.5e
OR
ciscocisco_ios_xe_softwareMatch16.9.1
OR
ciscocisco_ios_xe_softwareMatch16.9.1d
OR
ciscocisco_ios_xe_softwareMatch16.10.1
OR
ciscocisco_ios_xe_softwareMatch16.10.1e
OR
ciscocisco_ios_xe_softwareMatch16.11.1
OR
ciscocisco_ios_xe_softwareMatch16.11.1a
OR
ciscocisco_ios_xe_softwareMatch16.11.2
OR
ciscocisco_ios_xe_softwareMatch16.11.1s
OR
ciscocisco_ios_xe_softwareMatch16.11.1c
OR
ciscocisco_ios_xe_softwareMatch16.12.1
OR
ciscocisco_ios_xe_softwareMatch16.12.1s
OR
ciscocisco_ios_xe_softwareMatch16.12.1c
OR
ciscocisco_ios_xe_softwareMatch16.12.2
OR
ciscocisco_ios_xe_softwareMatch16.12.3
OR
ciscocisco_ios_xe_softwareMatch16.12.2s
OR
ciscocisco_ios_xe_softwareMatch16.12.2t
OR
ciscocisco_ios_xe_softwareMatch16.12.4
OR
ciscocisco_ios_xe_softwareMatch16.12.3s
OR
ciscocisco_ios_xe_softwareMatch17.1.1
OR
ciscocisco_ios_xe_softwareMatch17.1.1s
OR
ciscocisco_ios_xe_softwareMatch17.1.2
OR
ciscocisco_ios_xe_softwareMatch17.1.1t
OR
ciscocisco_ios_xe_softwareMatch17.2.1
VendorProductVersionCPE
ciscoios15.0eycpe:2.3:o:cisco:ios:15.0ey:*:*:*:*:*:*:*
ciscoios15.0eacpe:2.3:o:cisco:ios:15.0ea:*:*:*:*:*:*:*
ciscoios15.2ecpe:2.3:o:cisco:ios:15.2e:*:*:*:*:*:*:*
ciscoios15.2eycpe:2.3:o:cisco:ios:15.2ey:*:*:*:*:*:*:*
ciscoios15.2jazcpe:2.3:o:cisco:ios:15.2jaz:*:*:*:*:*:*:*
ciscoios15.2ebcpe:2.3:o:cisco:ios:15.2eb:*:*:*:*:*:*:*
ciscoios15.2eacpe:2.3:o:cisco:ios:15.2ea:*:*:*:*:*:*:*
ciscoios15.3jncpe:2.3:o:cisco:ios:15.3jn:*:*:*:*:*:*:*
ciscoios15.3jacpe:2.3:o:cisco:ios:15.3ja:*:*:*:*:*:*:*
ciscoios15.3jaacpe:2.3:o:cisco:ios:15.3jaa:*:*:*:*:*:*:*
Rows per page:
1-10 of 2541

EPSS

0

Percentile

5.1%

Related for CISCO-SA-XE-SAP-OPLBZE68