First published: Thu Sep 23 2021(Updated: )
A vulnerability in the Cisco IOS XE SD-WAN Software CLI could allow an authenticated, local attacker to overwrite arbitrary files on the local system. This vulnerability is due to improper access controls on files within the local file system. An attacker could exploit this vulnerability by placing a symbolic link in a specific location on the local file system. A successful exploit could allow the attacker to overwrite arbitrary files on an affected device.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco SD-WAN | <17.3.4 |
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sd-wan-GjR5pGOm
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-1612 is a vulnerability in the Cisco IOS XE SD-WAN Software CLI that allows an authenticated, local attacker to overwrite arbitrary files on the local system.
The severity of CVE-2021-1612 is high, with a severity value of 7.1.
CVE-2021-1612 affects all versions of Cisco SD-WAN up to and excluding version 17.3.4
An attacker can exploit CVE-2021-1612 by placing malicious files on the local system.
To fix CVE-2021-1612, apply the necessary software updates from Cisco.