CVE-2021-1540: Cisco ASR 5000 Series Software Authorization Bypass Vulnerabilities
Multiple vulnerabilities in the authorization process of Cisco ASR 5000 Series Software (StarOS) could allow an authenticated, remote attacker to bypass authorization and execute a subset of CLI commands on an affected device. For more information about these vulnerabilities, see the Details section of this advisory.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-1540?
CVE-2021-1540 is a vulnerability in the authorization process of Cisco ASR 5000 Series Software (StarOS) that could allow an authenticated, remote attacker to bypass authorization and execute a subset of CLI commands on an affected device.
How severe is CVE-2021-1540?
CVE-2021-1540 has a severity score of 7.2 out of 10, which is considered high severity.
Which software versions are affected by CVE-2021-1540?
CVE-2021-1540 affects Cisco ASR 5000 Series Software (StarOS) versions 21.16.9 to 21.20.8.
How can an attacker exploit CVE-2021-1540?
An authenticated, remote attacker can exploit CVE-2021-1540 by bypassing authorization and executing a subset of CLI commands on the affected device.
Is there a fix for CVE-2021-1540?
Cisco has released patches to address CVE-2021-1540. It is recommended to update to the latest version of Cisco ASR 5000 Series Software (StarOS) to mitigate this vulnerability.