CVE-2021-1437

HIGH

Cisco Aironet Series Access Points Software - Info Disclosure

Title source: llm
STIX 2.1

Description

A vulnerability in the FlexConnect Upgrade feature of Cisco Aironet Series Access Points Software could allow an unauthenticated, remote attacker to obtain confidential information from an affected device. This vulnerability is due to an unrestricted Trivial File Transfer Protocol (TFTP) configuration. An attacker could exploit this vulnerability by sending a specific TFTP request to an affected device. A successful exploit could allow the attacker to download any file from the filesystem of the affected access point (AP).

References (1)

Core 1

Scores

CVSS v3 7.5
EPSS 0.0048
EPSS Percentile 65.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-275
Status published
Products (3)
cisco/aironet_access_point_software
cisco/catalyst_9800_firmware 17.1 - 17.3.3
cisco/wireless_lan_controller_software 8.10.112.0 - 8.10.142.0
Published Mar 24, 2021
Tracked Since Feb 18, 2026