CVE Vulnerabilities

CVE-2021-1392

Insufficiently Protected Credentials

Published: Mar 24, 2021 | Modified: Nov 21, 2024
CVSS 3.x
7.8
HIGH
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
2.1 LOW
AV:L/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

A vulnerability in the CLI command permissions of Cisco IOS and Cisco IOS XE Software could allow an authenticated, local attacker to retrieve the password for Common Industrial Protocol (CIP) and then remotely configure the device as an administrative user. This vulnerability exists because incorrect permissions are associated with the show cip security CLI command. An attacker could exploit this vulnerability by issuing the command to retrieve the password for CIP on an affected device. A successful exploit could allow the attacker to reconfigure the device.

Weakness

The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.

Affected Software

NameVendorStart VersionEnd Version
IosCisco15.0(1)ey (including)15.0(1)ey (including)
IosCisco15.0(1)ey1 (including)15.0(1)ey1 (including)
IosCisco15.0(1)ey2 (including)15.0(1)ey2 (including)
IosCisco15.1(3)svs (including)15.1(3)svs (including)
IosCisco15.1(3)svt1 (including)15.1(3)svt1 (including)
IosCisco15.2(1)ey (including)15.2(1)ey (including)
IosCisco15.2(2)e (including)15.2(2)e (including)
IosCisco15.2(2)e1 (including)15.2(2)e1 (including)
IosCisco15.2(2)e2 (including)15.2(2)e2 (including)
IosCisco15.2(2)e3 (including)15.2(2)e3 (including)
IosCisco15.2(2)e4 (including)15.2(2)e4 (including)
IosCisco15.2(2)e5 (including)15.2(2)e5 (including)
IosCisco15.2(2)e5a (including)15.2(2)e5a (including)
IosCisco15.2(2)e5b (including)15.2(2)e5b (including)
IosCisco15.2(2)e6 (including)15.2(2)e6 (including)
IosCisco15.2(2)e7 (including)15.2(2)e7 (including)
IosCisco15.2(2)e7b (including)15.2(2)e7b (including)
IosCisco15.2(2)e8 (including)15.2(2)e8 (including)
IosCisco15.2(2)e9 (including)15.2(2)e9 (including)
IosCisco15.2(2)e10 (including)15.2(2)e10 (including)
IosCisco15.2(2)ea (including)15.2(2)ea (including)
IosCisco15.2(2)ea1 (including)15.2(2)ea1 (including)
IosCisco15.2(2)ea2 (including)15.2(2)ea2 (including)
IosCisco15.2(2)ea3 (including)15.2(2)ea3 (including)
IosCisco15.2(2)eb (including)15.2(2)eb (including)
IosCisco15.2(2)eb1 (including)15.2(2)eb1 (including)
IosCisco15.2(2)eb2 (including)15.2(2)eb2 (including)
IosCisco15.2(2a)e2 (including)15.2(2a)e2 (including)
IosCisco15.2(2b)e (including)15.2(2b)e (including)
IosCisco15.2(3)e1 (including)15.2(3)e1 (including)
IosCisco15.2(3)e2 (including)15.2(3)e2 (including)
IosCisco15.2(3)e3 (including)15.2(3)e3 (including)
IosCisco15.2(3)e4 (including)15.2(3)e4 (including)
IosCisco15.2(3)e5 (including)15.2(3)e5 (including)
IosCisco15.2(3)ea (including)15.2(3)ea (including)
IosCisco15.2(4)e5a (including)15.2(4)e5a (including)
IosCisco15.2(4)ea (including)15.2(4)ea (including)
IosCisco15.2(4)ea1 (including)15.2(4)ea1 (including)
IosCisco15.2(4)ea2 (including)15.2(4)ea2 (including)
IosCisco15.2(4)ea3 (including)15.2(4)ea3 (including)
IosCisco15.2(4)ea4 (including)15.2(4)ea4 (including)
IosCisco15.2(4)ea5 (including)15.2(4)ea5 (including)
IosCisco15.2(4)ea6 (including)15.2(4)ea6 (including)
IosCisco15.2(4)ea7 (including)15.2(4)ea7 (including)
IosCisco15.2(4)ea8 (including)15.2(4)ea8 (including)
IosCisco15.2(4)ea9 (including)15.2(4)ea9 (including)
IosCisco15.2(4)ea9a (including)15.2(4)ea9a (including)
IosCisco15.2(4)ea10 (including)15.2(4)ea10 (including)
IosCisco15.2(4)ec1 (including)15.2(4)ec1 (including)
IosCisco15.2(4)ec2 (including)15.2(4)ec2 (including)
IosCisco15.2(4)jaz (including)15.2(4)jaz (including)
IosCisco15.2(5)e (including)15.2(5)e (including)
IosCisco15.2(5)e1 (including)15.2(5)e1 (including)
IosCisco15.2(5)e2 (including)15.2(5)e2 (including)
IosCisco15.2(5)e2b (including)15.2(5)e2b (including)
IosCisco15.2(5)e2c (including)15.2(5)e2c (including)
IosCisco15.2(5)ea (including)15.2(5)ea (including)
IosCisco15.2(5a)e1 (including)15.2(5a)e1 (including)
IosCisco15.2(6)e (including)15.2(6)e (including)
IosCisco15.2(6)e0a (including)15.2(6)e0a (including)
IosCisco15.2(6)e0c (including)15.2(6)e0c (including)
IosCisco15.2(6)e1 (including)15.2(6)e1 (including)
IosCisco15.2(6)e1a (including)15.2(6)e1a (including)
IosCisco15.2(6)e1s (including)15.2(6)e1s (including)
IosCisco15.2(7)e0b (including)15.2(7)e0b (including)
IosCisco15.2(7a)e0b (including)15.2(7a)e0b (including)
IosCisco15.2(7b)e0b (including)15.2(7b)e0b (including)
IosCisco15.3(3)ja1 (including)15.3(3)ja1 (including)
IosCisco15.3(3)ja4 (including)15.3(3)ja4 (including)
IosCisco15.3(3)ja5 (including)15.3(3)ja5 (including)
IosCisco15.3(3)ja6 (including)15.3(3)ja6 (including)
IosCisco15.3(3)ja7 (including)15.3(3)ja7 (including)
IosCisco15.3(3)ja8 (including)15.3(3)ja8 (including)
IosCisco15.3(3)ja10 (including)15.3(3)ja10 (including)
IosCisco15.3(3)ja11 (including)15.3(3)ja11 (including)
IosCisco15.3(3)ja12 (including)15.3(3)ja12 (including)
IosCisco15.3(3)jaa (including)15.3(3)jaa (including)
IosCisco15.3(3)jax (including)15.3(3)jax (including)
IosCisco15.3(3)jax1 (including)15.3(3)jax1 (including)
IosCisco15.3(3)jax2 (including)15.3(3)jax2 (including)
IosCisco15.3(3)jb (including)15.3(3)jb (including)
IosCisco15.3(3)jbb (including)15.3(3)jbb (including)
IosCisco15.3(3)jbb1 (including)15.3(3)jbb1 (including)
IosCisco15.3(3)jbb2 (including)15.3(3)jbb2 (including)
IosCisco15.3(3)jbb4 (including)15.3(3)jbb4 (including)
IosCisco15.3(3)jbb5 (including)15.3(3)jbb5 (including)
IosCisco15.3(3)jbb6 (including)15.3(3)jbb6 (including)
IosCisco15.3(3)jbb6a (including)15.3(3)jbb6a (including)
IosCisco15.3(3)jbb8 (including)15.3(3)jbb8 (including)
IosCisco15.3(3)jc (including)15.3(3)jc (including)
IosCisco15.3(3)jc1 (including)15.3(3)jc1 (including)
IosCisco15.3(3)jc2 (including)15.3(3)jc2 (including)
IosCisco15.3(3)jc3 (including)15.3(3)jc3 (including)
IosCisco15.3(3)jc4 (including)15.3(3)jc4 (including)
IosCisco15.3(3)jc5 (including)15.3(3)jc5 (including)
IosCisco15.3(3)jc6 (including)15.3(3)jc6 (including)
IosCisco15.3(3)jc8 (including)15.3(3)jc8 (including)
IosCisco15.3(3)jc9 (including)15.3(3)jc9 (including)
IosCisco15.3(3)jc14 (including)15.3(3)jc14 (including)
IosCisco15.3(3)jd (including)15.3(3)jd (including)
IosCisco15.3(3)jd2 (including)15.3(3)jd2 (including)
IosCisco15.3(3)jd3 (including)15.3(3)jd3 (including)
IosCisco15.3(3)jd4 (including)15.3(3)jd4 (including)
IosCisco15.3(3)jd5 (including)15.3(3)jd5 (including)
IosCisco15.3(3)jd6 (including)15.3(3)jd6 (including)
IosCisco15.3(3)jd7 (including)15.3(3)jd7 (including)
IosCisco15.3(3)jd8 (including)15.3(3)jd8 (including)
IosCisco15.3(3)jd9 (including)15.3(3)jd9 (including)
IosCisco15.3(3)jd11 (including)15.3(3)jd11 (including)
IosCisco15.3(3)jd12 (including)15.3(3)jd12 (including)
IosCisco15.3(3)jd13 (including)15.3(3)jd13 (including)
IosCisco15.3(3)jd14 (including)15.3(3)jd14 (including)
IosCisco15.3(3)jd16 (including)15.3(3)jd16 (including)
IosCisco15.3(3)jd17 (including)15.3(3)jd17 (including)
IosCisco15.3(3)je (including)15.3(3)je (including)
IosCisco15.3(3)jf (including)15.3(3)jf (including)
IosCisco15.3(3)jf1 (including)15.3(3)jf1 (including)
IosCisco15.3(3)jf2 (including)15.3(3)jf2 (including)
IosCisco15.3(3)jf4 (including)15.3(3)jf4 (including)
IosCisco15.3(3)jf5 (including)15.3(3)jf5 (including)
IosCisco15.3(3)jf6 (including)15.3(3)jf6 (including)
IosCisco15.3(3)jf7 (including)15.3(3)jf7 (including)
IosCisco15.3(3)jf8 (including)15.3(3)jf8 (including)
IosCisco15.3(3)jf9 (including)15.3(3)jf9 (including)
IosCisco15.3(3)jf10 (including)15.3(3)jf10 (including)
IosCisco15.3(3)jf11 (including)15.3(3)jf11 (including)
IosCisco15.3(3)jf12 (including)15.3(3)jf12 (including)
IosCisco15.3(3)jf12i (including)15.3(3)jf12i (including)
IosCisco15.3(3)jf13 (including)15.3(3)jf13 (including)
IosCisco15.3(3)jg (including)15.3(3)jg (including)
IosCisco15.3(3)jg1 (including)15.3(3)jg1 (including)
IosCisco15.3(3)jh (including)15.3(3)jh (including)
IosCisco15.3(3)jh1 (including)15.3(3)jh1 (including)
IosCisco15.3(3)ji1 (including)15.3(3)ji1 (including)
IosCisco15.3(3)ji3 (including)15.3(3)ji3 (including)
IosCisco15.3(3)ji4 (including)15.3(3)ji4 (including)
IosCisco15.3(3)ji5 (including)15.3(3)ji5 (including)
IosCisco15.3(3)ji6 (including)15.3(3)ji6 (including)
IosCisco15.3(3)jj (including)15.3(3)jj (including)
IosCisco15.3(3)jj1 (including)15.3(3)jj1 (including)
IosCisco15.3(3)jk (including)15.3(3)jk (including)
IosCisco15.3(3)jk1 (including)15.3(3)jk1 (including)
IosCisco15.3(3)jk1t (including)15.3(3)jk1t (including)
IosCisco15.3(3)jk2 (including)15.3(3)jk2 (including)
IosCisco15.3(3)jk2a (including)15.3(3)jk2a (including)
IosCisco15.3(3)jk3 (including)15.3(3)jk3 (including)
IosCisco15.3(3)jk4 (including)15.3(3)jk4 (including)
IosCisco15.3(3)jn (including)15.3(3)jn (including)
IosCisco15.3(3)jn3 (including)15.3(3)jn3 (including)
IosCisco15.3(3)jn4 (including)15.3(3)jn4 (including)
IosCisco15.3(3)jn6 (including)15.3(3)jn6 (including)
IosCisco15.3(3)jn7 (including)15.3(3)jn7 (including)
IosCisco15.3(3)jn8 (including)15.3(3)jn8 (including)
IosCisco15.3(3)jn9 (including)15.3(3)jn9 (including)
IosCisco15.3(3)jn11 (including)15.3(3)jn11 (including)
IosCisco15.3(3)jn13 (including)15.3(3)jn13 (including)
IosCisco15.3(3)jn14 (including)15.3(3)jn14 (including)
IosCisco15.3(3)jn15 (including)15.3(3)jn15 (including)
IosCisco15.3(3)jnb (including)15.3(3)jnb (including)
IosCisco15.3(3)jnb1 (including)15.3(3)jnb1 (including)
IosCisco15.3(3)jnb2 (including)15.3(3)jnb2 (including)
IosCisco15.3(3)jnb3 (including)15.3(3)jnb3 (including)
IosCisco15.3(3)jnb4 (including)15.3(3)jnb4 (including)
IosCisco15.3(3)jnb5 (including)15.3(3)jnb5 (including)
IosCisco15.3(3)jnb6 (including)15.3(3)jnb6 (including)
IosCisco15.3(3)jnc (including)15.3(3)jnc (including)
IosCisco15.3(3)jnc1 (including)15.3(3)jnc1 (including)
IosCisco15.3(3)jnc2 (including)15.3(3)jnc2 (including)
IosCisco15.3(3)jnc3 (including)15.3(3)jnc3 (including)
IosCisco15.3(3)jnc4 (including)15.3(3)jnc4 (including)
IosCisco15.3(3)jnd (including)15.3(3)jnd (including)
IosCisco15.3(3)jnd1 (including)15.3(3)jnd1 (including)
IosCisco15.3(3)jnd2 (including)15.3(3)jnd2 (including)
IosCisco15.3(3)jnd3 (including)15.3(3)jnd3 (including)
IosCisco15.3(3)jnp (including)15.3(3)jnp (including)
IosCisco15.3(3)jnp1 (including)15.3(3)jnp1 (including)
IosCisco15.3(3)jnp3 (including)15.3(3)jnp3 (including)
IosCisco15.3(3)jpb (including)15.3(3)jpb (including)
IosCisco15.3(3)jpb1 (including)15.3(3)jpb1 (including)
IosCisco15.3(3)jpc (including)15.3(3)jpc (including)
IosCisco15.3(3)jpc1 (including)15.3(3)jpc1 (including)
IosCisco15.3(3)jpc2 (including)15.3(3)jpc2 (including)
IosCisco15.3(3)jpc3 (including)15.3(3)jpc3 (including)
IosCisco15.3(3)jpc5 (including)15.3(3)jpc5 (including)
IosCisco15.3(3)jpd (including)15.3(3)jpd (including)
Ios_xeCisco3.3.0xo (including)3.3.0xo (including)
Ios_xeCisco3.3.1xo (including)3.3.1xo (including)
Ios_xeCisco3.3.2xo (including)3.3.2xo (including)
Ios_xeCisco3.6.5be (including)3.6.5be (including)
Ios_xeCisco3.7.4e (including)3.7.4e (including)
Ios_xeCisco3.7.5e (including)3.7.5e (including)
Ios_xeCisco16.9.1 (including)16.9.1 (including)
Ios_xeCisco16.9.1d (including)16.9.1d (including)
Ios_xeCisco16.10.1 (including)16.10.1 (including)
Ios_xeCisco16.10.1e (including)16.10.1e (including)
Ios_xeCisco16.11.1 (including)16.11.1 (including)
Ios_xeCisco16.11.1a (including)16.11.1a (including)
Ios_xeCisco16.11.1c (including)16.11.1c (including)
Ios_xeCisco16.11.1s (including)16.11.1s (including)
Ios_xeCisco16.11.2 (including)16.11.2 (including)
Ios_xeCisco16.12.1 (including)16.12.1 (including)
Ios_xeCisco16.12.1c (including)16.12.1c (including)
Ios_xeCisco16.12.1s (including)16.12.1s (including)
Ios_xeCisco16.12.2 (including)16.12.2 (including)
Ios_xeCisco16.12.2s (including)16.12.2s (including)
Ios_xeCisco16.12.2t (including)16.12.2t (including)
Ios_xeCisco16.12.3 (including)16.12.3 (including)
Ios_xeCisco16.12.3s (including)16.12.3s (including)
Ios_xeCisco16.12.4 (including)16.12.4 (including)
Ios_xeCisco17.1.1 (including)17.1.1 (including)
Ios_xeCisco17.1.1s (including)17.1.1s (including)
Ios_xeCisco17.1.1t (including)17.1.1t (including)
Ios_xeCisco17.1.2 (including)17.1.2 (including)
Ios_xeCisco17.2.1 (including)17.2.1 (including)

Potential Mitigations

References