CVE-2021-34724
A vulnerability in the Cisco IOS XE SD-WAN Software CLI could allow an authenticated, local attacker to elevate privileges and execute arbitrary code on the underlying operating system as the root user. An attacker must be authenticated on an affected device as a PRIV15 user. This vulnerability is due to insufficient file system protection and the presence of a sensitive file in the bootflash directory on an affected device. An attacker could exploit this vulnerability by overwriting an installer file stored in the bootflash directory with arbitrary commands that can be executed with root-level privileges. A successful exploit could allow the attacker to read and write changes to the configuration database on the affected device.
EPSS 0.12% · 31.2th percentile
Risk Scores
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| cisco | ios_xe_sd-wan | 0 |
| Cisco | Cisco IOS XE SD-WAN Software | n/a |
Exploit Intelligence
Timeline
- Sep 23, 2021 EPSS Score
- Sep 23, 2021 CVE Published
- Nov 19, 2021 EPSS Score
- Jan 6, 2022 EPSS Score
- Jan 15, 2022 EPSS Score
- Mar 14, 2022 EPSS Score
- Apr 1, 2022 EPSS Score
- May 10, 2022 EPSS Score
- Jul 6, 2022 EPSS Score
- Sep 2, 2022 EPSS Score
- Oct 29, 2022 EPSS Score
- Dec 26, 2022 EPSS Score