CVE-2021-1419
Last modified
CVE-2021-1419 is a high-severity vulnerability rated 7.8/10 on the CVSS scale. A vulnerability in the SSH management feature of multiple Cisco Access Points (APs) platforms could allow a local, authenticated user to modify files on the affected device and possibly gain escalated privileges. The vulnerability is due to improper checking on file operations within the SSH management interface. EPSS estimates a 0.21% chance of exploitation in the next 30 days.
Description
A vulnerability in the SSH management feature of multiple Cisco Access Points (APs) platforms could allow a local, authenticated user to modify files on the affected device and possibly gain escalated privileges. The vulnerability is due to improper checking on file operations within the SSH management interface. A network administrator user could exploit this vulnerability by accessing an affected device through SSH management to make a configuration change. A successful exploit could allow the attacker to gain privileges equivalent to the root user.
Metrics
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Cisco | Aironet 1542d Firmware | All versions |
| Cisco | Aironet 1562d Firmware | All versions |
| Cisco | Aironet 1815m Firmware | All versions |
| Cisco | Aironet 1830e Firmware | All versions |
| Cisco | Aironet 1840i Firmware | All versions |
| Cisco | Aironet 1850e Firmware | All versions |
| Cisco | Aironet 2800i Firmware | All versions |
| Cisco | Aironet 3800p Firmware | All versions |
| Cisco | Aironet 4800 Firmware | All versions |
| Cisco | Catalyst 9105axi Firmware | All versions |
| Cisco | Catalyst 9115axe Firmware | All versions |
| Cisco | Catalyst 9117 Firmware | All versions |
| Cisco | Catalyst 9120axi Firmware | All versions |
| Cisco | Catalyst 9124axd Firmware | All versions |
| Cisco | Catalyst 9130axe Firmware | All versions |
| Cisco | Catalyst Iw6300 Ac Firmware | All versions |
| Cisco | Esw6300 Firmware | All versions |
| Cisco | 1100-8p Firmware | All versions |
| Cisco | 1120 Firmware | All versions |
| Cisco | 1160 Firmware | All versions |
| Cisco | Wireless Lan Controller Software | >= 8.10, < 8.10.151.0 |
| Cisco | Catalyst 9800 Firmware | >= 16.12, < 16.12.6 |
| Cisco | Catalyst 9800 Firmware | >= 17.3, < 17.3.3 |
| Cisco | Catalyst 9800 Firmware | 17.4 |
| Cisco | Aironet 1542i Firmware | All versions |
| Cisco | Aironet 1562e Firmware | All versions |
| Cisco | Aironet 1562i Firmware | All versions |
| Cisco | Aironet 1815w Firmware | All versions |
| Cisco | Aironet 1815t Firmware | All versions |
| Cisco | Aironet 1815i Firmware | All versions |
| Cisco | Aironet 1830i Firmware | All versions |
| Cisco | Aironet 1850i Firmware | All versions |
| Cisco | Aironet 2800e Firmware | All versions |
| Cisco | Aironet 3800i Firmware | All versions |
| Cisco | Aironet 3800e Firmware | All versions |
| Cisco | Catalyst 9105axw Firmware | All versions |
| Cisco | Catalyst 9115axi Firmware | All versions |
| Cisco | Catalyst 9120axp Firmware | All versions |
| Cisco | Catalyst 9120axe Firmware | All versions |
| Cisco | Catalyst 9124axi Firmware | All versions |
| Cisco | Catalyst 9130axi Firmware | All versions |
| Cisco | Catalyst Iw6300 Dc Firmware | All versions |
| Cisco | Catalyst Iw6300 Dcw Firmware | All versions |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2021-1419?
How severe is CVE-2021-1419?
How do I fix CVE-2021-1419?
Are you affected by CVE-2021-1419?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
