CVE-2021-1264

CRITICAL

Cisco Catalyst Center < 1.3.1.0 - Authenticated OS Command Injection via Command Runner Tool

Title source: llm
STIX 2.1

Description

A vulnerability in the Command Runner tool of Cisco DNA Center could allow an authenticated, remote attacker to perform a command injection attack. The vulnerability is due to insufficient input validation by the Command Runner tool. An attacker could exploit this vulnerability by providing crafted input during command execution or via a crafted command runner API call. A successful exploit could allow the attacker to execute arbitrary CLI commands on devices managed by Cisco DNA Center.

References (1)

Core 1
Core References

Scores

CVSS v3 9.6
EPSS 0.0078
EPSS Percentile 74.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-78
Status published
Products (1)
cisco/catalyst_center < 1.3.1.0
Published Jan 20, 2021
Tracked Since Feb 18, 2026