CVE-2021-1403: Cisco IOS XE Software Web UI Cross-Site WebSocket Hijacking Vulnerability
A vulnerability in the web UI feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to conduct a cross-site WebSocket hijacking (CSWSH) attack and cause a denial of service (DoS) condition on an affected device. This vulnerability is due to insufficient HTTP protections in the web UI on an affected device. An attacker could exploit this vulnerability by persuading an authenticated user of the web UI to follow a crafted link. A successful exploit could allow the attacker to corrupt memory on the affected device, forcing it to reload and causing a DoS condition.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-1403?
CVE-2021-1403 has been rated as a medium severity vulnerability.
How do I fix CVE-2021-1403?
To fix CVE-2021-1403, upgrade to a fixed version of Cisco IOS XE Software as recommended in the advisory.
Who is affected by CVE-2021-1403?
CVE-2021-1403 affects Cisco IOS XE Software versions 3.15.1xbs and various releases up to 17.3.2.
What type of attack does CVE-2021-1403 allow?
CVE-2021-1403 allows an unauthenticated remote attacker to perform a cross-site WebSocket hijacking attack.
What could be the impact of CVE-2021-1403?
The impact of CVE-2021-1403 could lead to a denial of service (DoS) condition on affected Cisco devices.