CVE-2021-1423: Cisco Aironet Access Points Arbitrary File Overwrite Vulnerability
A vulnerability in the implementation of a CLI command in Cisco Aironet Access Points (AP) could allow an authenticated, local attacker to overwrite files in the flash memory of the device. This vulnerability is due to insufficient input validation for a specific command. An attacker could exploit this vulnerability by issuing a command with crafted arguments. A successful exploit could allow the attacker to overwrite or create files with data that is already present in other files that are hosted on the affected device.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-1423?
CVE-2021-1423 is a vulnerability in the implementation of a CLI command in Cisco Aironet Access Points (AP) that could allow an authenticated, local attacker to overwrite files in the device's flash memory.
How severe is CVE-2021-1423?
CVE-2021-1423 has a severity value of 4.4 (medium).
Which software products are affected by CVE-2021-1423?
Cisco Aironet Access Point Software and Cisco Wireless LAN Controller Software are affected by CVE-2021-1423.
How can an attacker exploit CVE-2021-1423?
An attacker can exploit CVE-2021-1423 by exploiting insufficient input validation for a specific command in the CLI of the affected Cisco devices.
Where can I find more information about CVE-2021-1423?
You can find more information about CVE-2021-1423 in the Cisco Security Advisory at the following link: [Cisco Security Advisory](https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ap-foverwrt-HyVXvrtb)