Description
A vulnerability in the FlexConnect Upgrade feature of Cisco Aironet Series Access Points Software could allow an unauthenticated, remote attacker to obtain confidential information from an affected device. This vulnerability is due to an unrestricted Trivial File Transfer Protocol (TFTP) configuration. An attacker could exploit this vulnerability by sending a specific TFTP request to an affected device. A successful exploit could allow the attacker to download any file from the filesystem of the affected access point (AP).
Published: 2021-03-24
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2021-6904 A vulnerability in the FlexConnect Upgrade feature of Cisco Aironet Series Access Points Software could allow an unauthenticated, remote attacker to obtain confidential information from an affected device. This vulnerability is due to an unrestricted Trivial File Transfer Protocol (TFTP) configuration. An attacker could exploit this vulnerability by sending a specific TFTP request to an affected device. A successful exploit could allow the attacker to download any file from the filesystem of the affected access point (AP).
History

Sat, 09 Nov 2024 00:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Subscriptions

Cisco 1100 Integrated Services Router Aironet 1540 Aironet 1560 Aironet 1800 Aironet 2800 Aironet 3800 Aironet 4800 Aironet Access Point Software Catalyst 9100 Catalyst 9800 Catalyst 9800 Firmware Catalyst Iw6300 Esw6300 Wireless Lan Controller Software
cve-icon MITRE

Status: PUBLISHED

Assigner: cisco

Published:

Updated: 2024-11-08T23:35:47.063Z

Reserved: 2020-11-13T00:00:00.000Z

Link: CVE-2021-1437

cve-icon Vulnrichment

Updated: 2024-08-03T16:11:17.318Z

cve-icon NVD

Status : Modified

Published: 2021-03-24T20:15:14.900

Modified: 2024-11-21T05:44:21.730

Link: CVE-2021-1437

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses