CVE-2021-1299

HIGH

Cisco SD-WAN Firmware - Authenticated Command Injection

Title source: llm
STIX 2.1

Description

Multiple vulnerabilities in Cisco SD-WAN products could allow an authenticated attacker to perform command injection attacks against an affected device, which could allow the attacker to take certain actions with root privileges on the device. For more information about these vulnerabilities, see the Details section of this advisory.

References (1)

Core 1
Core References

Scores

CVSS v3 8.8
EPSS 0.0109
EPSS Percentile 78.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-20 CWE-77
Status published
Products (10)
cisco/catalyst_sd-wan_manager
cisco/sd-wan_firmware 18.2.0
cisco/sd-wan_firmware 18.3.0
cisco/sd-wan_firmware 18.3.8
cisco/sd-wan_firmware 18.4.6
cisco/sd-wan_firmware 19.2.3
cisco/sd-wan_firmware 19.2.99
cisco/sd-wan_firmware 20.1.0
cisco/sd-wan_vbond_orchestrator
cisco/sd-wan_vsmart_controller_firmware
Published Jan 20, 2021
Tracked Since Feb 18, 2026