CVE-2021-1443: Cisco IOS XE Software Web UI OS Command Injection Vulnerability
A vulnerability in the web UI of Cisco IOS XE Software could allow an authenticated, remote attacker to execute arbitrary code with root privileges on the underlying operating system of an affected device. The vulnerability exists because the affected software improperly sanitizes values that are parsed from a specific configuration file. An attacker could exploit this vulnerability by tampering with a specific configuration file and then sending an API call. A successful exploit could allow the attacker to inject arbitrary code that would be executed on the underlying operating system of the affected device. To exploit this vulnerability, the attacker would need to have a privileged set of credentials to the device.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-1443?
CVE-2021-1443 has a critical severity rating due to its potential to allow remote code execution with root privileges.
How do I fix CVE-2021-1443?
To fix CVE-2021-1443, upgrade to the patched versions of Cisco IOS XE as specified in Cisco's advisory.
What versions of Cisco IOS XE are affected by CVE-2021-1443?
CVE-2021-1443 affects various versions of Cisco IOS XE, including 16.9.1 through 17.2.1v.
Who can exploit CVE-2021-1443?
An authenticated, remote attacker can exploit CVE-2021-1443 to execute arbitrary code on affected devices.
What systems need to be monitored for CVE-2021-1443?
Systems running the vulnerable versions of Cisco IOS XE software need to be monitored for signs of exploitation related to CVE-2021-1443.