Cisco IOS XE Software SD WAN Arbitrary Command Execution (cisco-sa-iosxe-sdwarbcmdexec-sspOMUr3)

high Nessus Plugin ID 151374

Synopsis

The remote device is missing a vendor-supplied security patch

Description

A vulnerability in the CLI of Cisco IOS XE SD-WAN Software could allow an authenticated, local attacker to execute arbitrary commands on the underlying operating system as the root user. The attacker must be authenticated on the affected device as a low-privileged user to exploit this vulnerability. This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by injecting arbitrary commands to a file as a lower-privileged user. The commands are then executed on the device by the root user. A successful exploit could allow the attacker to execute arbitrary commands as the root user.

Please see the included Cisco BIDs and Cisco Security Advisory for more information.

Solution

Upgrade to the relevant fixed version referenced in Cisco bug ID CSCvu50633

See Also

http://www.nessus.org/u?0ab9978e

https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvu50633

Plugin Details

Severity: High

ID: 151374

File Name: cisco-sa-iosxe-sdwarbcmdexec-sspOMUr3-iosxe.nasl

Version: 1.7

Type: combined

Family: CISCO

Published: 7/6/2021

Updated: 9/24/2021

Supported Sensors: Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 6.7

CVSS v2

Risk Factor: Medium

Base Score: 6.9

Temporal Score: 5.1

Vector: CVSS2#AV:L/AC:M/Au:N/C:C/I:C/A:C

CVSS Score Source: CVE-2021-1432

CVSS v3

Risk Factor: High

Base Score: 7.3

Temporal Score: 6.4

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

CPE: cpe:/o:cisco:ios_xe

Required KB Items: Host/Cisco/IOS-XE/Version, Host/Cisco/IOS-XE/Model, Host/Cisco/SDWAN

Exploit Ease: No known exploits are available

Patch Publication Date: 3/24/2021

Vulnerability Publication Date: 3/24/2021

Reference Information

CVE: CVE-2021-1432

CWE: 20

CISCO-SA: cisco-sa-iosxe-sdwarbcmdexec-sspOMUr3

IAVA: 2021-A-0141-S

CISCO-BUG-ID: CSCvu50633