VDB

CVE-2021-1585

CVE-2021-1585 PUBLISHED CVSS 7.5 HIGH

A vulnerability in the Cisco Adaptive Security Device Manager (ASDM) Launcher could allow an unauthenticated, remote attacker to execute arbitrary code on a user's operating system. This vulnerability is due to a lack of proper signature verification for specific code exchanged between the ASDM and the Launcher. An attacker could exploit this vulnerability by leveraging a man-in-the-middle position on the network to intercept the traffic between the Launcher and the ASDM and then inject arbitrary code. A successful exploit could allow the attacker to execute arbitrary code on the user's operating system with the level of privileges assigned to the ASDM Launcher. A successful exploit may require the attacker to perform a social engineering attack to persuade the user to initiate communication from the Launcher to the ASDM.

EPSS 53.44% · 98.0th percentile

Risk Scores

CVSS 3.1
7.5
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS Score
53.44%
98.0th percentile

Affected Products

VendorProductVersions
ciscoadaptive_security_device_manager0
CiscoCisco Adaptive Security Appliance (ASA) Softwaren/a

Timeline

  • Apr 13, 2021 CVE Published
  • Jul 9, 2021 EPSS Score
  • Feb 4, 2022 EPSS Score
  • Apr 7, 2022 EPSS Score
  • Aug 17, 2022 EPSS Score
  • Aug 17, 2022 CVE Updated
  • Mar 22, 2024 EPSS Score
  • Jun 12, 2024 EPSS Score
  • Nov 10, 2024 EPSS Score
  • Mar 17, 2025 EPSS Score
  • Mar 20, 2025 EPSS Score
  • Mar 22, 2025 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›