Lucene search

K
cveCiscoCVE-2021-1233
HistoryJan 20, 2021 - 9:15 p.m.

CVE-2021-1233

2021-01-2021:15:11
CWE-20
cisco
web.nvd.nist.gov
63
2
cisco
sd-wan
software
cli
vulnerability
local attacker
sensitive information
nvd
cve-2021-1233

CVSS2

4.9

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

NONE

Availability Impact

NONE

AV:L/AC:L/Au:N/C:C/I:N/A:N

CVSS3

4.4

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N

AI Score

4.3

Confidence

High

EPSS

0

Percentile

5.1%

A vulnerability in the CLI of Cisco SD-WAN Software could allow an authenticated, local attacker to access sensitive information on an affected device. The vulnerability is due to insufficient input validation of requests that are sent to the iperf tool. An attacker could exploit this vulnerability by sending a crafted request to the iperf tool, which is included in Cisco SD-WAN Software. A successful exploit could allow the attacker to obtain any file from the filesystem of an affected device.

Affected configurations

Nvd
Node
ciscosd-wan_firmwareRange<18.4.3
AND
ciscovedge_100_routerMatch-
OR
ciscovedge_1000_routerMatch-
OR
ciscovedge_100b_routerMatch-
OR
ciscovedge_100m_routerMatch-
OR
ciscovedge_100wm_routerMatch-
OR
ciscovedge_2000_routerMatch-
OR
ciscovedge_5000_routerMatch-
OR
ciscovedge_cloud_routerMatch-
Node
ciscocatalyst_sd-wan_managerMatch-
OR
ciscosd-wan_vbond_orchestratorMatch-
VendorProductVersionCPE
ciscosd-wan_firmware*cpe:2.3:o:cisco:sd-wan_firmware:*:*:*:*:*:*:*:*
ciscovedge_100_router-cpe:2.3:h:cisco:vedge_100_router:-:*:*:*:*:*:*:*
ciscovedge_1000_router-cpe:2.3:h:cisco:vedge_1000_router:-:*:*:*:*:*:*:*
ciscovedge_100b_router-cpe:2.3:h:cisco:vedge_100b_router:-:*:*:*:*:*:*:*
ciscovedge_100m_router-cpe:2.3:h:cisco:vedge_100m_router:-:*:*:*:*:*:*:*
ciscovedge_100wm_router-cpe:2.3:h:cisco:vedge_100wm_router:-:*:*:*:*:*:*:*
ciscovedge_2000_router-cpe:2.3:h:cisco:vedge_2000_router:-:*:*:*:*:*:*:*
ciscovedge_5000_router-cpe:2.3:h:cisco:vedge_5000_router:-:*:*:*:*:*:*:*
ciscovedge_cloud_router-cpe:2.3:h:cisco:vedge_cloud_router:-:*:*:*:*:*:*:*
ciscocatalyst_sd-wan_manager-cpe:2.3:a:cisco:catalyst_sd-wan_manager:-:*:*:*:*:*:*:*
Rows per page:
1-10 of 111

CNA Affected

[
  {
    "product": "Cisco SD-WAN Solution",
    "vendor": "Cisco",
    "versions": [
      {
        "status": "affected",
        "version": "n/a"
      }
    ]
  }
]

Social References

More

CVSS2

4.9

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

NONE

Availability Impact

NONE

AV:L/AC:L/Au:N/C:C/I:N/A:N

CVSS3

4.4

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N

AI Score

4.3

Confidence

High

EPSS

0

Percentile

5.1%

Related for CVE-2021-1233