A vulnerability in the SSH management feature of multiple Cisco Access Points (APs) platforms could allow a local, authenticated user to modify files on the affected device and possibly gain escalated privileges. The vulnerability is due to improper checking on file operations within the SSH management interface. A network administrator user could exploit this vulnerability by accessing an affected device through SSH management to make a configuration change. A successful exploit could allow the attacker to gain privileges equivalent to the root user.

Project Subscriptions

Vendors Products
1100-8p Subscribe
1100-8p Firmware Subscribe
1120 Firmware Subscribe
1160 Firmware Subscribe
1160 Integrated Services Router Subscribe
Aironet 1542d Subscribe
Aironet 1542d Firmware Subscribe
Aironet 1542i Subscribe
Aironet 1542i Firmware Subscribe
Aironet 1562d Subscribe
Aironet 1562d Firmware Subscribe
Aironet 1562e Subscribe
Aironet 1562e Firmware Subscribe
Aironet 1562i Subscribe
Aironet 1562i Firmware Subscribe
Aironet 1815i Subscribe
Aironet 1815i Firmware Subscribe
Aironet 1815m Subscribe
Aironet 1815m Firmware Subscribe
Aironet 1815t Subscribe
Aironet 1815t Firmware Subscribe
Aironet 1815w Subscribe
Aironet 1815w Firmware Subscribe
Aironet 1830e Subscribe
Aironet 1830e Firmware Subscribe
Aironet 1830i Subscribe
Aironet 1830i Firmware Subscribe
Aironet 1840i Subscribe
Aironet 1840i Firmware Subscribe
Aironet 1850e Subscribe
Aironet 1850e Firmware Subscribe
Aironet 1850i Subscribe
Aironet 1850i Firmware Subscribe
Aironet 2800e Subscribe
Aironet 2800e Firmware Subscribe
Aironet 2800i Subscribe
Aironet 2800i Firmware Subscribe
Aironet 3800e Subscribe
Aironet 3800e Firmware Subscribe
Aironet 3800i Subscribe
Aironet 3800i Firmware Subscribe
Aironet 3800p Subscribe
Aironet 3800p Firmware Subscribe
Aironet 4800 Subscribe
Aironet 4800 Firmware Subscribe
Catalyst 9105axi Subscribe
Catalyst 9105axi Firmware Subscribe
Catalyst 9105axw Subscribe
Catalyst 9105axw Firmware Subscribe
Catalyst 9115axe Subscribe
Catalyst 9115axe Firmware Subscribe
Catalyst 9115axi Subscribe
Catalyst 9115axi Firmware Subscribe
Catalyst 9117 Firmware Subscribe
Catalyst 9117axi Subscribe
Catalyst 9120axe Subscribe
Catalyst 9120axe Firmware Subscribe
Catalyst 9120axi Subscribe
Catalyst 9120axi Firmware Subscribe
Catalyst 9120axp Subscribe
Catalyst 9120axp Firmware Subscribe
Catalyst 9124axd Subscribe
Catalyst 9124axd Firmware Subscribe
Catalyst 9124axi Subscribe
Catalyst 9124axi Firmware Subscribe
Catalyst 9130axe Subscribe
Catalyst 9130axe Firmware Subscribe
Catalyst 9130axi Subscribe
Catalyst 9130axi Firmware Subscribe
Catalyst 9800-40 Subscribe
Catalyst 9800-80 Subscribe
Catalyst 9800-cl Subscribe
Catalyst 9800-l Subscribe
Catalyst 9800 Firmware Subscribe
Catalyst Iw6300 Ac Subscribe
Catalyst Iw6300 Ac Firmware Subscribe
Catalyst Iw6300 Dc Subscribe
Catalyst Iw6300 Dc Firmware Subscribe
Catalyst Iw6300 Dcw Subscribe
Catalyst Iw6300 Dcw Firmware Subscribe
Esw6300 Subscribe
Esw6300 Firmware Subscribe
Wireless Lan Controller Software Subscribe
Advisories
Source ID Title
EUVD EUVD EUVD-2021-6886 A vulnerability in the SSH management feature of multiple Cisco Access Points (APs) platforms could allow a local, authenticated user to modify files on the affected device and possibly gain escalated privileges. The vulnerability is due to improper checking on file operations within the SSH management interface. A network administrator user could exploit this vulnerability by accessing an affected device through SSH management to make a configuration change. A successful exploit could allow the attacker to gain privileges equivalent to the root user.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Thu, 07 Nov 2024 22:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: cisco

Published:

Updated: 2024-11-07T21:52:19.550Z

Reserved: 2020-11-13T00:00:00

Link: CVE-2021-1419

cve-icon Vulnrichment

Updated: 2024-08-03T16:11:17.241Z

cve-icon NVD

Status : Modified

Published: 2021-09-23T03:15:07.697

Modified: 2024-11-21T05:44:19.193

Link: CVE-2021-1419

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses