CVE-2021-1612: Cisco IOS XE SD-WAN Software Arbitrary File Overwrite Vulnerability
A vulnerability in the Cisco IOS XE SD-WAN Software CLI could allow an authenticated, local attacker to overwrite arbitrary files on the local system. This vulnerability is due to improper access controls on files within the local file system. An attacker could exploit this vulnerability by placing a symbolic link in a specific location on the local file system. A successful exploit could allow the attacker to overwrite arbitrary files on an affected device.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2021-1612?
CVE-2021-1612 is a vulnerability in the Cisco IOS XE SD-WAN Software CLI that allows an authenticated, local attacker to overwrite arbitrary files on the local system.
What is the severity of CVE-2021-1612?
The severity of CVE-2021-1612 is high, with a severity value of 7.1.
How does CVE-2021-1612 affect Cisco SD-WAN?
CVE-2021-1612 affects all versions of Cisco SD-WAN up to and excluding version 17.3.4
How can an attacker exploit CVE-2021-1612?
An attacker can exploit CVE-2021-1612 by placing malicious files on the local system.
What is the recommended action to fix CVE-2021-1612?
To fix CVE-2021-1612, apply the necessary software updates from Cisco.