CVE-2021-1419
| Summary |
A vulnerability in the SSH management feature of multiple Cisco Access Points (APs) platforms could allow a local, authenticated user to modify files on the affected device and possibly gain escalated privileges. The vulnerability is due to improper checking on file operations within the SSH management interface. A network administrator user could exploit this vulnerability by accessing an affected device through SSH management to make a configuration change. A successful exploit could allow the attacker to gain privileges equivalent to the root user.
|
| Publication Date |
Sept. 23, 2021, 12:15 p.m. |
| Registration Date |
Sept. 23, 2021, 4:09 p.m. |
| Last Update |
Nov. 21, 2024, 2:44 p.m. |
|
CVSS3.1 : HIGH
|
| スコア |
7.8
|
| Vector |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
| 攻撃元区分(AV) |
ローカル |
| 攻撃条件の複雑さ(AC) |
低 |
| 攻撃に必要な特権レベル(PR) |
低 |
| 利用者の関与(UI) |
不要 |
| 影響の想定範囲(S) |
変更なし |
| 機密性への影響(C) |
高 |
| 完全性への影響(I) |
高 |
| 可用性への影響(A) |
高 |
|
CVSS2.0 : HIGH
|
| Score |
7.2
|
| Vector |
AV:L/AC:L/Au:N/C:C/I:C/A:C |
| 攻撃元区分(AV) |
ローカル |
| 攻撃条件の複雑さ(AC) |
低 |
| 攻撃前の認証要否(Au) |
不要 |
| 機密性への影響(C) |
高 |
| 完全性への影響(I) |
高 |
| 可用性への影響(A) |
高 |
| Get all privileges. |
いいえ
|
| Get user privileges |
いいえ
|
| Get other privileges |
いいえ
|
| User operation required |
いいえ
|
Affected software configurations
| Configuration1 |
or higher |
or less |
more than |
less than |
| cpe:2.3:o:cisco:aironet_1542d_firmware:-:*:*:*:*:*:*:* |
|
|
|
|
| execution environment |
| 1 |
cpe:2.3:h:cisco:aironet_1542d:-:*:*:*:*:*:*:* |
| Configuration2 |
or higher |
or less |
more than |
less than |
| cpe:2.3:o:cisco:aironet_1562d_firmware:-:*:*:*:*:*:*:* |
|
|
|
|
| execution environment |
| 1 |
cpe:2.3:h:cisco:aironet_1562d:-:*:*:*:*:*:*:* |
| Configuration3 |
or higher |
or less |
more than |
less than |
| cpe:2.3:o:cisco:aironet_1815m_firmware:-:*:*:*:*:*:*:* |
|
|
|
|
| execution environment |
| 1 |
cpe:2.3:h:cisco:aironet_1815m:-:*:*:*:*:*:*:* |
| Configuration4 |
or higher |
or less |
more than |
less than |
| cpe:2.3:o:cisco:aironet_1830e_firmware:-:*:*:*:*:*:*:* |
|
|
|
|
| execution environment |
| 1 |
cpe:2.3:h:cisco:aironet_1830e:-:*:*:*:*:*:*:* |
| Configuration5 |
or higher |
or less |
more than |
less than |
| cpe:2.3:o:cisco:aironet_1840i_firmware:-:*:*:*:*:*:*:* |
|
|
|
|
| execution environment |
| 1 |
cpe:2.3:h:cisco:aironet_1840i:-:*:*:*:*:*:*:* |
| Configuration6 |
or higher |
or less |
more than |
less than |
| cpe:2.3:o:cisco:aironet_1850e_firmware:-:*:*:*:*:*:*:* |
|
|
|
|
| execution environment |
| 1 |
cpe:2.3:h:cisco:aironet_1850e:-:*:*:*:*:*:*:* |
| Configuration7 |
or higher |
or less |
more than |
less than |
| cpe:2.3:o:cisco:aironet_2800i_firmware:-:*:*:*:*:*:*:* |
|
|
|
|
| execution environment |
| 1 |
cpe:2.3:h:cisco:aironet_2800i:-:*:*:*:*:*:*:* |
| Configuration8 |
or higher |
or less |
more than |
less than |
| cpe:2.3:o:cisco:aironet_3800p_firmware:-:*:*:*:*:*:*:* |
|
|
|
|
| execution environment |
| 1 |
cpe:2.3:h:cisco:aironet_3800p:-:*:*:*:*:*:*:* |
| Configuration9 |
or higher |
or less |
more than |
less than |
| cpe:2.3:o:cisco:aironet_4800_firmware:-:*:*:*:*:*:*:* |
|
|
|
|
| execution environment |
| 1 |
cpe:2.3:h:cisco:aironet_4800:-:*:*:*:*:*:*:* |
| Configuration10 |
or higher |
or less |
more than |
less than |
| cpe:2.3:o:cisco:catalyst_9105axi_firmware:-:*:*:*:*:*:*:* |
|
|
|
|
| execution environment |
| 1 |
cpe:2.3:h:cisco:catalyst_9105axi:-:*:*:*:*:*:*:* |
| Configuration11 |
or higher |
or less |
more than |
less than |
| cpe:2.3:o:cisco:catalyst_9115axe_firmware:-:*:*:*:*:*:*:* |
|
|
|
|
| execution environment |
| 1 |
cpe:2.3:h:cisco:catalyst_9115axe:-:*:*:*:*:*:*:* |
| Configuration12 |
or higher |
or less |
more than |
less than |
| cpe:2.3:o:cisco:catalyst_9117_firmware:-:*:*:*:*:*:*:* |
|
|
|
|
| execution environment |
| 1 |
cpe:2.3:h:cisco:catalyst_9117axi:-:*:*:*:*:*:*:* |
| Configuration13 |
or higher |
or less |
more than |
less than |
| cpe:2.3:o:cisco:catalyst_9120axi_firmware:-:*:*:*:*:*:*:* |
|
|
|
|
| execution environment |
| 1 |
cpe:2.3:h:cisco:catalyst_9120axi:-:*:*:*:*:*:*:* |
| Configuration14 |
or higher |
or less |
more than |
less than |
| cpe:2.3:o:cisco:catalyst_9124axd_firmware:-:*:*:*:*:*:*:* |
|
|
|
|
| execution environment |
| 1 |
cpe:2.3:h:cisco:catalyst_9124axd:-:*:*:*:*:*:*:* |
| Configuration15 |
or higher |
or less |
more than |
less than |
| cpe:2.3:o:cisco:catalyst_9130axe_firmware:-:*:*:*:*:*:*:* |
|
|
|
|
| execution environment |
| 1 |
cpe:2.3:h:cisco:catalyst_9130axe:-:*:*:*:*:*:*:* |
| Configuration16 |
or higher |
or less |
more than |
less than |
| cpe:2.3:o:cisco:catalyst_iw6300_ac_firmware:-:*:*:*:*:*:*:* |
|
|
|
|
| execution environment |
| 1 |
cpe:2.3:h:cisco:catalyst_iw6300_ac:-:*:*:*:*:*:*:* |
| Configuration17 |
or higher |
or less |
more than |
less than |
| cpe:2.3:o:cisco:esw6300_firmware:-:*:*:*:*:*:*:* |
|
|
|
|
| execution environment |
| 1 |
cpe:2.3:h:cisco:esw6300:-:*:*:*:*:*:*:* |
| Configuration18 |
or higher |
or less |
more than |
less than |
| cpe:2.3:o:cisco:1100-8p_firmware:-:*:*:*:*:*:*:* |
|
|
|
|
| execution environment |
| 1 |
cpe:2.3:h:cisco:1100-8p:-:*:*:*:*:*:*:* |
| Configuration19 |
or higher |
or less |
more than |
less than |
| cpe:2.3:o:cisco:1120_firmware:-:*:*:*:*:*:*:* |
|
|
|
|
| execution environment |
| 1 |
cpe:2.3:h:cisco:1120:-:*:*:*:*:*:*:* |
| Configuration20 |
or higher |
or less |
more than |
less than |
| cpe:2.3:o:cisco:1160_firmware:-:*:*:*:*:*:*:* |
|
|
|
|
| execution environment |
| 1 |
cpe:2.3:h:cisco:1160_integrated_services_router:-:*:*:*:*:*:*:* |
| Configuration21 |
or higher |
or less |
more than |
less than |
| cpe:2.3:a:cisco:wireless_lan_controller_software:*:*:*:*:*:*:*:* |
8.10 |
|
|
8.10.151.0 |
| Configuration22 |
or higher |
or less |
more than |
less than |
| cpe:2.3:o:cisco:catalyst_9800_firmware:*:*:*:*:*:*:*:* |
16.12 |
|
|
16.12.6 |
| cpe:2.3:o:cisco:catalyst_9800_firmware:*:*:*:*:*:*:*:* |
17.3 |
|
|
17.3.3 |
| cpe:2.3:o:cisco:catalyst_9800_firmware:17.4:*:*:*:*:*:*:* |
|
|
|
|
| execution environment |
| 1 |
cpe:2.3:h:cisco:catalyst_9800-l:-:*:*:*:*:*:*:* |
| Configuration23 |
or higher |
or less |
more than |
less than |
| cpe:2.3:o:cisco:aironet_1542i_firmware:-:*:*:*:*:*:*:* |
|
|
|
|
| execution environment |
| 1 |
cpe:2.3:h:cisco:aironet_1542i:-:*:*:*:*:*:*:* |
| Configuration24 |
or higher |
or less |
more than |
less than |
| cpe:2.3:o:cisco:catalyst_9800_firmware:*:*:*:*:*:*:*:* |
16.12 |
|
|
16.12.6 |
| cpe:2.3:o:cisco:catalyst_9800_firmware:*:*:*:*:*:*:*:* |
17.3 |
|
|
17.3.3 |
| cpe:2.3:o:cisco:catalyst_9800_firmware:17.4:*:*:*:*:*:*:* |
|
|
|
|
| execution environment |
| 1 |
cpe:2.3:h:cisco:catalyst_9800-cl:-:*:*:*:*:*:*:* |
| Configuration25 |
or higher |
or less |
more than |
less than |
| cpe:2.3:o:cisco:catalyst_9800_firmware:*:*:*:*:*:*:*:* |
16.12 |
|
|
16.12.6 |
| cpe:2.3:o:cisco:catalyst_9800_firmware:*:*:*:*:*:*:*:* |
17.3 |
|
|
17.3.3 |
| cpe:2.3:o:cisco:catalyst_9800_firmware:17.4:*:*:*:*:*:*:* |
|
|
|
|
| execution environment |
| 1 |
cpe:2.3:h:cisco:catalyst_9800-40:-:*:*:*:*:*:*:* |
| Configuration26 |
or higher |
or less |
more than |
less than |
| cpe:2.3:o:cisco:catalyst_9800_firmware:*:*:*:*:*:*:*:* |
16.12 |
|
|
16.12.6 |
| cpe:2.3:o:cisco:catalyst_9800_firmware:*:*:*:*:*:*:*:* |
17.3 |
|
|
17.3.3 |
| cpe:2.3:o:cisco:catalyst_9800_firmware:17.4:*:*:*:*:*:*:* |
|
|
|
|
| execution environment |
| 1 |
cpe:2.3:h:cisco:catalyst_9800-80:-:*:*:*:*:*:*:* |
| Configuration27 |
or higher |
or less |
more than |
less than |
| cpe:2.3:o:cisco:aironet_1562e_firmware:-:*:*:*:*:*:*:* |
|
|
|
|
| execution environment |
| 1 |
cpe:2.3:h:cisco:aironet_1562e:-:*:*:*:*:*:*:* |
| Configuration28 |
or higher |
or less |
more than |
less than |
| cpe:2.3:o:cisco:aironet_1562i_firmware:-:*:*:*:*:*:*:* |
|
|
|
|
| execution environment |
| 1 |
cpe:2.3:h:cisco:aironet_1562i:-:*:*:*:*:*:*:* |
| Configuration29 |
or higher |
or less |
more than |
less than |
| cpe:2.3:o:cisco:aironet_1815w_firmware:-:*:*:*:*:*:*:* |
|
|
|
|
| execution environment |
| 1 |
cpe:2.3:h:cisco:aironet_1815w:-:*:*:*:*:*:*:* |
| Configuration30 |
or higher |
or less |
more than |
less than |
| cpe:2.3:o:cisco:aironet_1815t_firmware:-:*:*:*:*:*:*:* |
|
|
|
|
| execution environment |
| 1 |
cpe:2.3:h:cisco:aironet_1815t:-:*:*:*:*:*:*:* |
| Configuration31 |
or higher |
or less |
more than |
less than |
| cpe:2.3:o:cisco:aironet_1815i_firmware:-:*:*:*:*:*:*:* |
|
|
|
|
| execution environment |
| 1 |
cpe:2.3:h:cisco:aironet_1815i:-:*:*:*:*:*:*:* |
| Configuration32 |
or higher |
or less |
more than |
less than |
| cpe:2.3:o:cisco:aironet_1830i_firmware:-:*:*:*:*:*:*:* |
|
|
|
|
| execution environment |
| 1 |
cpe:2.3:h:cisco:aironet_1830i:-:*:*:*:*:*:*:* |
| Configuration33 |
or higher |
or less |
more than |
less than |
| cpe:2.3:o:cisco:aironet_1850i_firmware:-:*:*:*:*:*:*:* |
|
|
|
|
| execution environment |
| 1 |
cpe:2.3:h:cisco:aironet_1850i:-:*:*:*:*:*:*:* |
| Configuration34 |
or higher |
or less |
more than |
less than |
| cpe:2.3:o:cisco:aironet_2800e_firmware:-:*:*:*:*:*:*:* |
|
|
|
|
| execution environment |
| 1 |
cpe:2.3:h:cisco:aironet_2800e:-:*:*:*:*:*:*:* |
| Configuration35 |
or higher |
or less |
more than |
less than |
| cpe:2.3:o:cisco:aironet_3800i_firmware:-:*:*:*:*:*:*:* |
|
|
|
|
| execution environment |
| 1 |
cpe:2.3:h:cisco:aironet_3800i:-:*:*:*:*:*:*:* |
| Configuration36 |
or higher |
or less |
more than |
less than |
| cpe:2.3:o:cisco:aironet_3800e_firmware:-:*:*:*:*:*:*:* |
|
|
|
|
| execution environment |
| 1 |
cpe:2.3:h:cisco:aironet_3800e:-:*:*:*:*:*:*:* |
| Configuration37 |
or higher |
or less |
more than |
less than |
| cpe:2.3:o:cisco:catalyst_9105axw_firmware:-:*:*:*:*:*:*:* |
|
|
|
|
| execution environment |
| 1 |
cpe:2.3:h:cisco:catalyst_9105axw:-:*:*:*:*:*:*:* |
| Configuration38 |
or higher |
or less |
more than |
less than |
| cpe:2.3:o:cisco:catalyst_9115axi_firmware:-:*:*:*:*:*:*:* |
|
|
|
|
| execution environment |
| 1 |
cpe:2.3:h:cisco:catalyst_9115axi:-:*:*:*:*:*:*:* |
| Configuration39 |
or higher |
or less |
more than |
less than |
| cpe:2.3:o:cisco:catalyst_9120axp_firmware:-:*:*:*:*:*:*:* |
|
|
|
|
| execution environment |
| 1 |
cpe:2.3:h:cisco:catalyst_9120axp:-:*:*:*:*:*:*:* |
| Configuration40 |
or higher |
or less |
more than |
less than |
| cpe:2.3:o:cisco:catalyst_9120axe_firmware:-:*:*:*:*:*:*:* |
|
|
|
|
| execution environment |
| 1 |
cpe:2.3:h:cisco:catalyst_9120axe:-:*:*:*:*:*:*:* |
| Configuration41 |
or higher |
or less |
more than |
less than |
| cpe:2.3:o:cisco:catalyst_9124axi_firmware:-:*:*:*:*:*:*:* |
|
|
|
|
| execution environment |
| 1 |
cpe:2.3:h:cisco:catalyst_9124axi:-:*:*:*:*:*:*:* |
| Configuration42 |
or higher |
or less |
more than |
less than |
| cpe:2.3:o:cisco:catalyst_9130axi_firmware:-:*:*:*:*:*:*:* |
|
|
|
|
| execution environment |
| 1 |
cpe:2.3:h:cisco:catalyst_9130axi:-:*:*:*:*:*:*:* |
| Configuration43 |
or higher |
or less |
more than |
less than |
| cpe:2.3:o:cisco:catalyst_iw6300_dc_firmware:-:*:*:*:*:*:*:* |
|
|
|
|
| execution environment |
| 1 |
cpe:2.3:h:cisco:catalyst_iw6300_dc:-:*:*:*:*:*:*:* |
| Configuration44 |
or higher |
or less |
more than |
less than |
| cpe:2.3:o:cisco:catalyst_iw6300_dcw_firmware:-:*:*:*:*:*:*:* |
|
|
|
|
| execution environment |
| 1 |
cpe:2.3:h:cisco:catalyst_iw6300_dcw:-:*:*:*:*:*:*:* |
Related information, measures and tools
Common Vulnerabilities List
JVN Vulnerability Information
複数の Cisco Access Points プラットフォームにおける脆弱性
| Title |
複数の Cisco Access Points プラットフォームにおける脆弱性
|
| Summary |
複数の Cisco Access Points (APs) プラットフォームには、不特定の脆弱性が存在します。
|
| Possible impacts |
情報を取得される、情報を改ざんされる、およびサービス運用妨害 (DoS) 状態にされる可能性があります。 |
| Solution |
ベンダより正式な対策が公開されています。ベンダ情報を参照して適切な対策を実施してください。 |
| Publication Date |
Sept. 22, 2021, midnight |
| Registration Date |
Sept. 1, 2022, 2:30 p.m. |
| Last Update |
Sept. 1, 2022, 2:30 p.m. |
Affected System
| シスコシステムズ |
|
Cisco Aironet 1542d シリーズファームウェア
|
|
Cisco Aironet 1562d シリーズファームウェア
|
|
Cisco Aironet 1815m シリーズファームウェア
|
|
Cisco Aironet 1830e シリーズファームウェア
|
|
Cisco Aironet 1840i シリーズファームウェア
|
|
Cisco Aironet 1850e シリーズファームウェア
|
|
Cisco Aironet 2800i シリーズファームウェア
|
|
Cisco Aironet 3800p シリーズファームウェア
|
|
Cisco Aironet 4800 シリーズファームウェア
|
|
Cisco Catalyst 9105axi シリーズファームウェア
|
CVE (情報セキュリティ 共通脆弱性識別子)
CWE (共通脆弱性タイプ一覧)
ベンダー情報
Change Log
| No |
Changed Details |
Date of change |
| 1 |
[2022年09月01日] 掲載 |
Sept. 1, 2022, 2:30 p.m. |