First published: Sat May 22 2021(Updated: )
Multiple vulnerabilities in Cisco DNA Spaces Connector could allow an authenticated, remote attacker to perform a command injection attack on an affected device. These vulnerabilities are due to insufficient input sanitization when executing affected commands. A high-privileged attacker could exploit these vulnerabilities on a Cisco DNA Spaces Connector by injecting crafted input during command execution. A successful exploit could allow the attacker to execute arbitrary commands as root within the Connector docker container.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco DNA Spaces: Connector | <2.0.519 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for the Cisco DNA Spaces Connector vulnerability is CVE-2021-1560.
The severity rating of the Cisco DNA Spaces Connector vulnerability is critical with a CVSS score of 7.2.
The affected software for the Cisco DNA Spaces Connector vulnerability is Cisco DNA Spaces Connector version up to and exclusive of 2.0.519.
The risk of the Cisco DNA Spaces Connector vulnerability is an authenticated, remote attacker could perform a command injection attack on an affected device.
To fix the Cisco DNA Spaces Connector vulnerability, it is recommended to upgrade to a version later than 2.0.519.