CVE-2021-1391: Cisco IOS and IOS XE Software Privilege Escalation Vulnerability
A vulnerability in the dragonite debugger of Cisco IOS XE Software could allow an authenticated, local attacker to escalate from privilege level 15 to root privilege. The vulnerability is due to the presence of development testing and verification scripts that remained on the device. An attacker could exploit this vulnerability by bypassing the consent token mechanism with the residual scripts on the affected device. A successful exploit could allow the attacker to escalate from privilege level 15 to root privilege.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-1391?
CVE-2021-1391 has been assigned a high CVSS score indicating significant potential impact.
How do I fix CVE-2021-1391?
To fix CVE-2021-1391, upgrade to a fixed version of Cisco IOS XE software as recommended by Cisco.
Who is affected by CVE-2021-1391?
CVE-2021-1391 affects authenticated users with local access to Cisco IOS XE devices running specific versions.
What types of attacks are possible with CVE-2021-1391?
CVE-2021-1391 allows attackers to escalate privileges from level 15 to root, potentially compromising the device.
Is CVE-2021-1391 exploitable remotely?
CVE-2021-1391 is not exploitable remotely as it requires authenticated local access to the affected device.