CVE-2021-3459

MEDIUM

Motorola MM1000 Firmware - Privilege Escalation and OS Command Injection via Web Server

Title source: llm
STIX 2.1

Description

A privilege escalation vulnerability was reported in the MM1000 device configuration web server, which could allow privileged shell access and/or arbitrary privileged commands to be executed on the adapter.

References (1)

Core 1
Core References
Mitigation, Vendor Advisory x_refsource_misc
https://motorolamentor.zendesk.com/hc/en-us/articles/1260804047750

Scores

CVSS v3 6.8
EPSS 0.0029
EPSS Percentile 21.1%
Attack Vector PHYSICAL
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-78
Status published
Products (1)
motorola/mm1000_firmware
Published Aug 17, 2021
Tracked Since Feb 18, 2026