IT

Tracker / CVE-2021-1423

CVE-2021-1423

Medium 4.4

A vulnerability in the implementation of a CLI command in Cisco Aironet Access Points (AP) could allow an authenticated, local attacker to overwrite files in the flash memory of the device. This vulnerability is due to insufficient input validation for a specific command. An attacker could exploit this vulnerability by issuing a command with crafted arguments. A successful exploit could allow the attacker to overwrite or create files with data that is already present in other files that are hosted on the affected device.

Affected products and versions

cisco aironet_access_point_software
cisco catalyst_9800_firmware · … → 16.12.5
cisco catalyst_9800_firmware · 17.1 → 17.2
cisco wireless_lan_controller_software · … → 8.5.171.0
cisco wireless_lan_controller_software · 8.6 → 8.10.130.0

Analysis

This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.

References