CVE-2021-1435: Cisco IOS XE Software Web UI Command Injection Vulnerability
Cisco IOS XE contains a command injection vulnerability in the web user interface that could allow a remote, authenticated attacker to inject commands that can be executed as the root user.
Other sources
A vulnerability in the web UI of Cisco IOS XE Software could allow an authenticated, remote attacker to inject arbitrary commands that can be executed as the root user. This vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by sending a crafted request to the web UI of an affected device with arbitrary commands injected into a portion of the request. A successful exploit could allow the attacker to execute arbitrary commands as the root user.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2021-1435?
CVE-2021-1435 is a vulnerability in the web UI of Cisco IOS XE Software that allows an authenticated, remote attacker to inject arbitrary commands as the root user.
How severe is CVE-2021-1435?
CVE-2021-1435 has a severity rating of 7.2, which is considered critical.
What software is affected by CVE-2021-1435?
Cisco IOS XE Web UI is affected by CVE-2021-1435.
How can an attacker exploit CVE-2021-1435?
An attacker can exploit CVE-2021-1435 by sending a crafted request to the web UI.
Are there any references for CVE-2021-1435?
Yes, you can find more information about CVE-2021-1435 at the following references: [Link 1](https://blog.talosintelligence.com/active-exploitation-of-cisco-ios-xe-software/), [Link 2](https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-iosxe-webcmdinjsh-UFJxTgZD)