First published: Thu Apr 08 2021(Updated: )
A vulnerability in the CLI of Cisco IOS XR Software could allow an authenticated, local attacker to inject arbitrary commands that are executed with root privileges on the underlying Linux operating system (OS) of an affected device. This vulnerability is due to insufficient input validation of commands that are supplied by the user. An attacker could exploit this vulnerability by authenticating to a device and submitting crafted input to an affected command. A successful exploit could allow the attacker to execute commands on the underlying Linux OS with root privileges.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco IOS XR | <7.3.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this Cisco IOS XR Software vulnerability is CVE-2021-1485.
The severity level of CVE-2021-1485 is high, with a severity value of 7.8.
This vulnerability allows an authenticated, local attacker to inject arbitrary commands with root privileges on the underlying Linux operating system of the affected device.
This vulnerability affects Cisco IOS XR Software up to and excluding version 7.3.1.
To fix this vulnerability, it is recommended to upgrade to a version of Cisco IOS XR Software that is not affected by this issue.