CVE Vulnerabilities

CVE-2021-1381

Active Debug Code

Published: Mar 24, 2021 | Modified: Mar 30, 2021
CVSS 3.x
6.1
MEDIUM
Source:
NVD
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
CVSS 2.x
3.6 LOW
AV:L/AC:L/Au:N/C:P/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu

A vulnerability in Cisco IOS XE Software could allow an authenticated, local attacker with high privileges or an unauthenticated attacker with physical access to the device to open a debugging console. The vulnerability is due to insufficient command authorization restrictions. An attacker could exploit this vulnerability by running commands on the hardware platform to open a debugging console. A successful exploit could allow the attacker to access a debugging console.

Weakness

The application is deployed to unauthorized actors with debugging code still enabled or active, which can create unintended entry points or expose sensitive information.

Affected Software

Name Vendor Start Version End Version
Ios_xe Cisco 16.11.1 16.11.1
Ios_xe Cisco 16.11.1a 16.11.1a
Ios_xe Cisco 16.11.1b 16.11.1b
Ios_xe Cisco 16.11.1c 16.11.1c
Ios_xe Cisco 16.11.1s 16.11.1s
Ios_xe Cisco 16.11.2 16.11.2
Ios_xe Cisco 16.12.1 16.12.1
Ios_xe Cisco 16.12.1a 16.12.1a
Ios_xe Cisco 16.12.1c 16.12.1c
Ios_xe Cisco 16.12.1s 16.12.1s
Ios_xe Cisco 16.12.1t 16.12.1t
Ios_xe Cisco 16.12.1w 16.12.1w
Ios_xe Cisco 16.12.1x 16.12.1x
Ios_xe Cisco 16.12.1y 16.12.1y
Ios_xe Cisco 16.12.1z 16.12.1z
Ios_xe Cisco 16.12.1za 16.12.1za
Ios_xe Cisco 16.12.2 16.12.2
Ios_xe Cisco 16.12.2a 16.12.2a
Ios_xe Cisco 16.12.2s 16.12.2s
Ios_xe Cisco 16.12.2t 16.12.2t
Ios_xe Cisco 16.12.3 16.12.3
Ios_xe Cisco 16.12.3a 16.12.3a
Ios_xe Cisco 16.12.3s 16.12.3s
Ios_xe Cisco 16.12.4 16.12.4
Ios_xe Cisco 16.12.4a 16.12.4a
Ios_xe Cisco 17.1.1 17.1.1
Ios_xe Cisco 17.1.1a 17.1.1a
Ios_xe Cisco 17.1.1s 17.1.1s
Ios_xe Cisco 17.1.1t 17.1.1t
Ios_xe Cisco 17.1.2 17.1.2
Ios_xe Cisco 17.2.1 17.2.1
Ios_xe Cisco 17.2.1a 17.2.1a
Ios_xe Cisco 17.2.1r 17.2.1r
Ios_xe Cisco 17.2.1v 17.2.1v
Ios_xe Cisco 17.2.2 17.2.2
Ios_xe Cisco 17.2.3 17.2.3

Potential Mitigations

References