VDB

CVE-2021-1261

CVE-2021-1261 PUBLISHED CVSS 8.100000381469727 HIGH

Multiple vulnerabilities in Cisco SD-WAN products could allow an authenticated attacker to perform command injection attacks against an affected device, which could allow the attacker to take certain actions with root privileges on the device. For more information about these vulnerabilities, see the Details section of this advisory.

EPSS 1.28% · 80.0th percentile

Risk Scores

CVSS 3.0
8.100000381469727
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
EPSS Score
1.28%
80.0th percentile

Affected Products

VendorProductVersions
ciscosd-wan_firmware20.1.0, 18.2.0, 18.3.0
ciscosd-wan_vbond_orchestrator
ciscosd-wan_vsmart_controller_firmware
CiscoCisco SD-WAN Solutionn/a
ciscocatalyst_sd-wan_manager

Timeline

  • Jan 20, 2021 CVE Published
  • Apr 14, 2021 EPSS Score
  • Jun 23, 2021 EPSS Score
  • Aug 24, 2021 EPSS Score
  • Dec 27, 2021 EPSS Score
  • Jan 6, 2022 EPSS Score
  • Feb 28, 2022 EPSS Score
  • May 1, 2022 EPSS Score
  • Jul 3, 2022 EPSS Score
  • Sep 4, 2022 EPSS Score
  • Jan 8, 2023 EPSS Score
  • Mar 7, 2023 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›