CVE-2021-1539: Cisco ASR 5000 Series Software Authorization Bypass Vulnerabilities
Multiple vulnerabilities in the authorization process of Cisco ASR 5000 Series Software (StarOS) could allow an authenticated, remote attacker to bypass authorization and execute a subset of CLI commands on an affected device. For more information about these vulnerabilities, see the Details section of this advisory.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-1539?
CVE-2021-1539 is a vulnerability in the authorization process of Cisco ASR 5000 Series Software (StarOS) that could allow an authenticated, remote attacker to bypass authorization and execute a subset of CLI commands on an affected device.
What is the severity of CVE-2021-1539?
CVE-2021-1539 has a severity score of 8.8 (high).
How does CVE-2021-1539 affect Cisco ASR 5000 Series Software (StarOS)?
CVE-2021-1539 affects Cisco ASR 5000 Series Software (StarOS) versions 21.16.9 to 21.20.8.
How can an attacker exploit CVE-2021-1539?
An authenticated, remote attacker can exploit CVE-2021-1539 by bypassing authorization and executing a subset of CLI commands on an affected device.
Is there a fix available for CVE-2021-1539?
Yes, Cisco has released software updates to address CVE-2021-1539. It is recommended to update to the latest available version.