CVE-2021-1375: Cisco IOS XE Software Fast Reload Vulnerabilities
Multiple vulnerabilities in the fast reload feature of Cisco IOS XE Software running on Cisco Catalyst 3850, Cisco Catalyst 9300, and Cisco Catalyst 9300L Series Switches could allow an authenticated, local attacker to either execute arbitrary code on the underlying operating system, install and boot a malicious software image, or execute unsigned binaries on an affected device. These vulnerabilities are due to improper checks performed by system boot routines. To exploit these vulnerabilities, the attacker would need privileged access to the CLI of the device. A successful exploit could allow the attacker to either execute arbitrary code on the underlying operating system or execute unsigned code and bypass the image verification check part of the secure boot process. For more information about these vulnerabilities, see the Details section of this advisory.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-1375?
The severity level of CVE-2021-1375 is rated as high.
How do I fix CVE-2021-1375?
To fix CVE-2021-1375, you should upgrade to a non-vulnerable version of Cisco IOS XE Software.
What devices are affected by CVE-2021-1375?
CVE-2021-1375 affects Cisco Catalyst 3850, 9300, and 9300L Series Switches.
What type of attack can exploit CVE-2021-1375?
An authenticated local attacker can exploit CVE-2021-1375 to execute arbitrary code on the underlying operating system.
Is CVE-2021-1375 being actively exploited?
As of now, there are no public reports indicating that CVE-2021-1375 is being actively exploited in the wild.