CVE-2021-1419
—CVSS 3.1
7.8 high
EPSS
<1%p12
Published
()
Modified
Description
A vulnerability in the SSH management feature of multiple Cisco Access Points (APs) platforms could allow a local, authenticated user to modify files on the affected device and possibly gain escalated privileges. The vulnerability is due to improper checking on file operations within the SSH management interface. A network administrator user could exploit this vulnerability by accessing an affected device through SSH management to make a configuration change. A successful exploit could allow the attacker to gain privileges equivalent to the root user.
- Vendors
- cisco
- Products
- aironet 1542d firmware, aironet 1562d firmware, aironet 1815m firmware, aironet 1830e firmware, aironet 1840i firmware, aironet 1850e firmware, aironet 2800i firmware, aironet 3800p firmware, aironet 4800 firmware, catalyst 9105axi firmware, catalyst 9115axe firmware, catalyst 9117 firmware
- Weakness
- CWE-284
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.