CVE-2021-1281

MEDIUM

Cisco IOS XE SD-WAN - Authenticated Privilege Escalation to Root via Concurrent CLI Sessions

Title source: llm
STIX 2.1

Description

A vulnerability in CLI management in Cisco IOS XE SD-WAN Software could allow an authenticated, local attacker to access the underlying operating system as the root user. This vulnerability is due to the way the software handles concurrent CLI sessions. An attacker could exploit this vulnerability by authenticating to the device as an administrative user and executing a sequence of commands. A successful exploit could allow the attacker to obtain access to the underlying operating system as the root user.

References (1)

Core 1
Core References

Scores

CVSS v3 5.1
EPSS 0.0004
EPSS Percentile 12.7%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-399
Status published
Products (50)
cisco/ios_xe 16.9.1
cisco/ios_xe 16.9.2
cisco/ios_xe 16.9.3
cisco/ios_xe 16.9.4
cisco/ios_xe 16.10.1
cisco/ios_xe 16.10.1a
cisco/ios_xe 16.10.1b
cisco/ios_xe 16.10.1c
cisco/ios_xe 16.10.1d
cisco/ios_xe 16.10.1e
... and 40 more
Published Mar 24, 2021
Tracked Since Feb 18, 2026