VDB

CVE-2021-1419

CVE-2021-1419 PUBLISHED CVSS 7.800000190734863 HIGH

A vulnerability in the SSH management feature of multiple Cisco Access Points (APs) platforms could allow a local, authenticated user to modify files on the affected device and possibly gain escalated privileges. The vulnerability is due to improper checking on file operations within the SSH management interface. A network administrator user could exploit this vulnerability by accessing an affected device through SSH management to make a configuration change. A successful exploit could allow the attacker to gain privileges equivalent to the root user.

EPSS 0.04% · 11.1th percentile

Risk Scores

CVSS 3.1
7.800000190734863
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS Score
0.04%
11.1th percentile

Affected Products

VendorProductVersions
ciscocatalyst_iw6300_ac_firmware
ciscocatalyst_9800_firmware17.4, 17.3, 17.4
ciscocatalyst_9115axi_firmware
ciscocatalyst_9124axi_firmware
ciscowireless_lan_controller_software8.10
ciscoaironet_3800i_firmware
ciscoaironet_1850i_firmware
ciscocatalyst_9105axw_firmware
ciscocatalyst_9130axe_firmware
ciscoaironet_1830i_firmware
ciscocatalyst_iw6300_dcw_firmware
ciscoaironet_3800e_firmware
CiscoCisco Wireless LAN Controller (WLC)n/a
ciscoaironet_1840i_firmware
ciscoaironet_1542d_firmware
ciscocatalyst_9120axi_firmware
ciscocatalyst_9120axp_firmware
cisco1160_firmware
ciscoaironet_1562i_firmware
ciscocatalyst_9105axi_firmware

…and 22 more

Timeline

  • Apr 13, 2021 CVE Published
  • Sep 23, 2021 EPSS Score
  • Oct 5, 2021 EPSS Score
  • Oct 11, 2021 EPSS Score
  • Jan 6, 2022 EPSS Score
  • Jan 15, 2022 EPSS Score
  • Mar 14, 2022 EPSS Score
  • Apr 1, 2022 EPSS Score
  • May 10, 2022 EPSS Score
  • Jul 6, 2022 EPSS Score
  • Oct 29, 2022 EPSS Score
  • Dec 26, 2022 EPSS Score

References

Open in Interactive Console →
$ Console Community · 100/wk Open console ›