VDB

CVE-2021-1512

CVE-2021-1512 PUBLISHED CVSS 4.400000095367432 MEDIUM

A vulnerability in the CLI of Cisco SD-WAN Software could allow an authenticated, local attacker to overwrite arbitrary files in the underlying file system of an affected system. This vulnerability is due to insufficient validation of the user-supplied input parameters of a specific CLI command. An attacker could exploit this vulnerability by issuing that command with specific parameters. A successful exploit could allow the attacker to overwrite the content in any arbitrary files that reside on the underlying host file system.

EPSS 0.06% · 18.4th percentile

Risk Scores

CVSS 3.0
4.400000095367432
CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N
EPSS Score
0.06%
18.4th percentile

Affected Products

VendorProductVersions
ciscovedge_1000_firmware
ciscosd-wan_vmanage20.1, 0
ciscovedge_cloud_firmware
ciscosd-wan_vbond_orchestrator
ciscocatalyst_sd-wan_manager19.2, 20.3, 20.4
ciscovedge_100m_firmware
ciscovedge_2000_firmware
ciscovedge-100b_firmware
ciscovedge_100b_firmware
ciscovsmart_controller_firmware
ciscovedge_100_firmware
ciscovedge_100wm_firmware
ciscovedge_5000_firmware
CiscoCisco SD-WAN Solutionn/a

Timeline

  • Apr 13, 2021 CVE Published
  • May 7, 2021 EPSS Score
  • Jul 10, 2021 EPSS Score
  • Sep 10, 2021 EPSS Score
  • Nov 11, 2021 EPSS Score
  • Jan 6, 2022 EPSS Score
  • Mar 15, 2022 EPSS Score
  • Apr 1, 2022 EPSS Score
  • May 16, 2022 EPSS Score
  • Jul 18, 2022 EPSS Score
  • Sep 17, 2022 EPSS Score
  • Nov 18, 2022 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›