Description
A vulnerability in the implementation of a CLI command in Cisco Aironet Access Points (AP) could allow an authenticated, local attacker to overwrite files in the flash memory of the device. This vulnerability is due to insufficient input validation for a specific command. An attacker could exploit this vulnerability by issuing a command with crafted arguments. A successful exploit could allow the attacker to overwrite or create files with data that is already present in other files that are hosted on the affected device.
Published: 2021-03-24
Score: 4.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2021-6890 A vulnerability in the implementation of a CLI command in Cisco Aironet Access Points (AP) could allow an authenticated, local attacker to overwrite files in the flash memory of the device. This vulnerability is due to insufficient input validation for a specific command. An attacker could exploit this vulnerability by issuing a command with crafted arguments. A successful exploit could allow the attacker to overwrite or create files with data that is already present in other files that are hosted on the affected device.
History

Sat, 09 Nov 2024 00:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Subscriptions

Cisco 1100 Integrated Services Router Aironet 1540 Aironet 1560 Aironet 1800 Aironet 2800 Aironet 3800 Aironet 4800 Aironet Access Point Software Catalyst 9100 Catalyst 9800 Catalyst 9800 Firmware Catalyst Iw6300 Esw6300 Wireless Lan Controller Software
cve-icon MITRE

Status: PUBLISHED

Assigner: cisco

Published:

Updated: 2024-11-08T23:30:28.527Z

Reserved: 2020-11-13T00:00:00.000Z

Link: CVE-2021-1423

cve-icon Vulnrichment

Updated: 2024-08-03T16:11:16.924Z

cve-icon NVD

Status : Modified

Published: 2021-03-24T21:15:13.443

Modified: 2024-11-21T05:44:19.837

Link: CVE-2021-1423

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses