CVE-2021-1436: Cisco IOS XE SD-WAN Software Path Traversal Vulnerability
A vulnerability in the CLI of Cisco IOS XE SD-WAN Software could allow an authenticated, local attacker to conduct path traversal attacks and obtain read access to sensitive files on an affected system. This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by sending a crafted request to an affected system. A successful exploit could allow the attacker to view arbitrary files on the affected system.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-1436?
The severity of CVE-2021-1436 is considered high due to its potential for path traversal attacks allowing unauthorized read access to sensitive files.
How do I fix CVE-2021-1436?
To fix CVE-2021-1436, update your Cisco IOS XE SD-WAN Software to a version that includes the relevant security patches.
What are the affected versions for CVE-2021-1436?
CVE-2021-1436 affects multiple versions of Cisco IOS XE SD-WAN Software including 3.15.1xbs, 16.11.x, 16.12.x, and 17.1.x.
Who can exploit CVE-2021-1436?
CVE-2021-1436 can be exploited by authenticated local attackers who can conduct path traversal attacks.
What causes the vulnerability CVE-2021-1436?
CVE-2021-1436 is caused by insufficient validation of user-supplied input in the Command Line Interface (CLI) of the affected software.