Cisco Security Advisories · May 2021 — Cisco Security Advisories
37 advisories 72 CVEs 2 EXPLOITED

PSIRT bulletins (cisco-sa-*) and cross-source CVEs naming Cisco for 2021-05. Mirrored into Vulnetix VDB.

Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity). 2 are already weaponised in the wild — see the Exploited section.

Advisories

cisco-sa-ade-xcvAQEOZ

Cisco PSIRTHIGH2021-05-19

Cisco ADE-OS Local File Inclusion Vulnerability

CVEs:CVE-2021-1306

Affected products

ProductStatusVendorPackageEcosystem
CVRFPID-111903 affected Cisco
CVRFPID-190324 affected Cisco
CVRFPID-213688 affected Cisco
Upstream advisory

cisco-sa-pi-epnm-cmd-inj-YU5e6tB3

Cisco PSIRTHIGH2021-05-19

Cisco Prime Infrastructure and Cisco Evolved Programmable Network Manager Command Injection Vulnerability

CVEs:CVE-2021-1487

Affected products

ProductStatusVendorPackageEcosystem
CVRFPID-190324 affected Cisco
CVRFPID-213688 affected Cisco
Upstream advisory

cisco-sa-wifi-faf-22epcEWu

Cisco PSIRTHIGH2021-05-11

Multiple Vulnerabilities in Frame Aggregation and Fragmentation Implementations of 802.11 Specification Affecting Cisco Products: May 2021

CVEs:CVE-2020-26144CVE-2020-26141CVE-2020-26146CVE-2020-26147CVE-2020-26140CVE-2020-26142CVE-2020-26143CVE-2020-26145CVE-2020-26139CVE-2020-24587CVE-2020-24586CVE-2020-24588

Affected products

ProductStatusVendorPackageEcosystem
CVRFPID-190024 affected Cisco
CVRFPID-277607 affected Cisco
CVRFPID-278404 affected Cisco
CVRFPID-278888 affected Cisco
CVRFPID-280012 affected Cisco
CVRFPID-280019 affected Cisco
Upstream advisory

cisco-sa-esa-wsa-sma-info-gY2AEz2H

Cisco PSIRTHIGH2021-05-05

Cisco Content Security Management Appliance, Email Security Appliance, and Web Security Appliance Information Disclosure Vulnerability

CVEs:CVE-2021-1516

Affected products

ProductStatusVendorPackageEcosystem
CVRFPID-189789 affected Cisco
CVRFPID-189790 affected Cisco
CVRFPID-189791 affected Cisco
Upstream advisory

cisco-sa-sdwan-arbfile-7Qhd9mCn

Cisco PSIRTHIGH2021-05-05

Cisco SD-WAN Software Arbitrary File Corruption Vulnerability

CVEs:CVE-2021-1512

Affected products

ProductStatusVendorPackageEcosystem
CVRFPID-238692 affected Cisco
CVRFPID-271450 affected Cisco
CVRFPID-278041 affected Cisco
CVRFPID-278078 affected Cisco
CVRFPID-278124 affected Cisco
Upstream advisory

cisco-sa-sdwan-dos-Ckn5cVqW

Cisco PSIRTHIGH2021-05-05

Cisco SD-WAN Software vDaemon Denial of Service Vulnerability

CVEs:CVE-2021-1513

Affected products

ProductStatusVendorPackageEcosystem
CVRFPID-238692 affected Cisco
CVRFPID-271450 affected Cisco
CVRFPID-278041 affected Cisco
CVRFPID-278078 affected Cisco
CVRFPID-278124 affected Cisco
Upstream advisory

cisco-sa-sdwan-privesc-QVszVUPy

Cisco PSIRTHIGH2021-05-05

Cisco SD-WAN Software Privilege Escalation Vulnerability

CVEs:CVE-2021-1514

Affected products

ProductStatusVendorPackageEcosystem
CVRFPID-238692 affected Cisco
CVRFPID-271450 affected Cisco
CVRFPID-278041 affected Cisco
CVRFPID-278078 affected Cisco
CVRFPID-278124 affected Cisco
Upstream advisory

Need live exploit intelligence?

Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.