Rewterz
Rewterz Threat Advisory – Multiple SAP NetWeaver Vulnerabilities
April 14, 2021
Rewterz
Rewterz Threat Alert – BRATA Is the Banking Trojan To Look Out For
April 14, 2021

Rewterz Threat Advisory – CVE-2021-1391 – Cisco IOS and IOS XE Software Privilege Escalation Vulnerability

Severity

Medium

Analysis Summary

CVE-2021-1391

Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, local attacker to escalate from privilege level 15 to root privilege.due to the presence of development testing and verification scripts that remained on the device. An attacker could exploit this vulnerability by bypassing the consent token mechanism with the residual scripts on the affected device. A successful exploit could allow the attacker to escalate from privilege level 15 to root privilege.

Impact

Privilege Escalation

Affected Vendors

Cisco

Affected Products

  • catalyst IE 3200 rugged series switch
  • catalyst IE3300 rugged series switch
  • catalyst IE 3400 Rugged series switch
  • catalyst IE 3400 Heavy duty series switch
  • Embedded Services 3300 series switch(ESS 3300)

Remediation

Refer to cisco advisory for the complete list of affected product and their respective patches.

https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-XE-FSM-Yj8qJbJc