CVE-2021-34723: Cisco IOS XE SD-WAN Software Arbitrary File Overwrite Vulnerability
A vulnerability in a specific CLI command that is run on Cisco IOS XE SD-WAN Software could allow an authenticated, local attacker to overwrite arbitrary files in the configuration database of an affected device. This vulnerability is due to insufficient validation of specific CLI command parameters. An attacker could exploit this vulnerability by issuing that command with specific parameters. A successful exploit could allow the attacker to overwrite the content of the configuration database and gain root-level access to an affected device.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2021-34723.
What is the severity of CVE-2021-34723?
The severity of CVE-2021-34723 is medium with a severity value of 6.7.
Which software is affected by CVE-2021-34723?
Cisco IOS XE SD-WAN Software version 17.3.1a is affected by CVE-2021-34723.
How does CVE-2021-34723 work?
CVE-2021-34723 allows an authenticated, local attacker to overwrite arbitrary files in the configuration database of an affected device by exploiting a vulnerability in a specific CLI command.
How can I fix CVE-2021-34723?
To fix CVE-2021-34723, it is recommended to upgrade to a fixed version of Cisco IOS XE SD-WAN Software.