A vulnerability in the CLI of Cisco IOS XE SD-WAN Software could allow an authenticated, local attacker to inject arbitrary commands to be executed with root-level privileges on the underlying operating system. This vulnerability is due to insufficient input validation on certain CLI commands. An attacker could exploit this vulnerability by authenticating to an affected device and submitting crafted input to the CLI. The attacker must be authenticated as an administrative user to execute the affected commands. A successful exploit could allow the attacker to execute commands with root-level privileges.

Project Subscriptions

Vendors Products
1000 Integrated Services Router Subscribe
1100-4g\/6g Integrated Services Router Subscribe
1100-4p Integrated Services Router Subscribe
1100-8p Integrated Services Router Subscribe
1100 Integrated Services Router Subscribe
1101-4p Integrated Services Router Subscribe
1101 Integrated Services Router Subscribe
1109-2p Integrated Services Router Subscribe
1109-4p Integrated Services Router Subscribe
1109 Integrated Services Router Subscribe
1111x-8p Integrated Services Router Subscribe
1111x Integrated Services Router Subscribe
111x Integrated Services Router Subscribe
1120 Integrated Services Router Subscribe
1160 Integrated Services Router Subscribe
4000 Integrated Services Router Subscribe
4221 Integrated Services Router Subscribe
422 Integrated Services Router Subscribe
4321 Integrated Services Router Subscribe
4331 Integrated Services Router Subscribe
4351 Integrated Services Router Subscribe
4431 Integrated Services Router Subscribe
4451-x Integrated Services Router Subscribe
4451 Integrated Services Router Subscribe
4461 Integrated Services Router Subscribe
Asr 1000 Subscribe
Asr 1000-esp100 Subscribe
Asr 1000-x Subscribe
Asr 1000 Series Subscribe
Asr 1000 Series Route Processor \(rp2\) Subscribe
Asr 1000 Series Route Processor \(rp3\) Subscribe
Asr 1001 Subscribe
Asr 1001-hx Subscribe
Asr 1001-hx R Subscribe
Asr 1001-x Subscribe
Asr 1001-x R Subscribe
Asr 1002 Subscribe
Asr 1002-hx Subscribe
Asr 1002-hx R Subscribe
Asr 1002-x Subscribe
Asr 1002-x R Subscribe
Asr 1004 Subscribe
Asr 1006 Subscribe
Asr 1006-x Subscribe
Asr 1009-x Subscribe
Asr 1013 Subscribe
Asr 1023 Subscribe
Csr 1000v Subscribe
Ios Xe Sd-wan Subscribe
Advisories
Source ID Title
EUVD EUVD EUVD-2021-21375 A vulnerability in the CLI of Cisco IOS XE SD-WAN Software could allow an authenticated, local attacker to inject arbitrary commands to be executed with root-level privileges on the underlying operating system. This vulnerability is due to insufficient input validation on certain CLI commands. An attacker could exploit this vulnerability by authenticating to an affected device and submitting crafted input to the CLI. The attacker must be authenticated as an administrative user to execute the affected commands. A successful exploit could allow the attacker to execute commands with root-level privileges.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: cisco

Published:

Updated: 2024-11-07T21:58:45.239Z

Reserved: 2021-06-15T00:00:00

Link: CVE-2021-34725

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2021-09-23T03:15:19.093

Modified: 2024-11-21T06:11:03.450

Link: CVE-2021-34725

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses