CVE-2021-1299: Cisco SD-WAN Command Injection Vulnerabilities
Multiple vulnerabilities in Cisco SD-WAN products could allow an authenticated attacker to perform command injection attacks against an affected device, which could allow the attacker to take certain actions with root privileges on the device. For more information about these vulnerabilities, see the Details section of this advisory.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for these multiple vulnerabilities in Cisco SD-WAN products?
The vulnerability ID for these multiple vulnerabilities in Cisco SD-WAN products is CVE-2021-1299.
What are the affected software versions of Cisco SD-WAN products?
The affected software versions of Cisco SD-WAN products are 18.2.0, 18.3.0, 18.3.8, 18.4.6, 19.2.3, 19.2.99, and 20.1.0.
What actions can an authenticated attacker perform with root privileges on an affected device?
An authenticated attacker can perform command injection attacks against an affected device, allowing them to take certain actions with root privileges.
What is the severity rating of vulnerability CVE-2021-1299?
The severity rating of vulnerability CVE-2021-1299 is critical, with a severity value of 8.8.
How can I fix the vulnerabilities in Cisco SD-WAN products?
To fix the vulnerabilities in Cisco SD-WAN products, it is recommended to upgrade to a fixed software release as mentioned in the Cisco Security Advisory.