First published: Sat May 22 2021(Updated: )
Multiple vulnerabilities in Cisco DNA Spaces Connector could allow an authenticated, local attacker to elevate privileges and execute arbitrary commands on the underlying operating system as root. These vulnerabilities are due to insufficient restrictions during the execution of affected CLI commands. An attacker could exploit these vulnerabilities by leveraging the insufficient restrictions during execution of these commands. A successful exploit could allow the attacker to elevate privileges from dnasadmin and execute arbitrary commands on the underlying operating system as root.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco DNA Spaces | <2.3.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-1558 is a vulnerability in Cisco DNA Spaces Connector that can allow an authenticated local attacker to elevate privileges and execute arbitrary commands as root.
The severity of CVE-2021-1558 is high, with a CVSS score of 6.7.
An attacker can exploit CVE-2021-1558 by leveraging insufficient restrictions during the execution of affected CLI commands.
The affected software for CVE-2021-1558 is Cisco DNA Spaces Connector version up to 2.3.1.
Yes, Cisco has provided a fix for CVE-2021-1558. Please refer to the Cisco Security Advisory for more information.