CVE-2021-1359
Cisco Web Security Appliance Privilege Escalation Vulnerability
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
A vulnerability in the configuration management of Cisco AsyncOS for Cisco Web Security Appliance (WSA) could allow an authenticated, remote attacker to perform command injection and elevate privileges to root. This vulnerability is due to insufficient validation of user-supplied XML input for the web interface. An attacker could exploit this vulnerability by uploading crafted XML configuration files that contain scripting code to a vulnerable device. A successful exploit could allow the attacker to execute arbitrary commands on the underlying operating system and elevate privileges to root. An attacker would need a valid user account with the rights to upload configuration files to exploit this vulnerability.
Una vulnerabilidad en la administración de la configuración de Cisco AsyncOS para Cisco Web Security Appliance (WSA), podría permitir a un atacante remoto autenticado llevar a cabo una inyección de comandos y elevar los privilegios a root. Esta vulnerabilidad se presenta debido a que la comprobación de la entrada XML suministrada por el usuario para la interfaz web es insuficiente. Un atacante podría explotar esta vulnerabilidad al cargar archivos de configuración XML diseñados que contengan código de scripting en un dispositivo vulnerable. Una explotación con éxito podría permitir al atacante ejecutar comandos arbitrarios en el sistema operativo subyacente y elevar los privilegios a root. Un atacante necesitaría una cuenta de usuario válida con los derechos para cargar archivos de configuración para explotar esta vulnerabilidad
CVSS Scores
SSVC
- Decision:Track
Timeline
- 2020-11-13 CVE Reserved
- 2021-07-08 CVE Published
- 2023-03-07 EPSS Updated
- 2024-11-07 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-112: Missing XML Validation
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Cisco Search vendor "Cisco" | Web Security Appliance Search vendor "Cisco" for product "Web Security Appliance" | 11.8.0-429 Search vendor "Cisco" for product "Web Security Appliance" and version "11.8.0-429" | - |
Affected
| ||||||
Cisco Search vendor "Cisco" | Web Security Appliance Search vendor "Cisco" for product "Web Security Appliance" | 11.8.0-453 Search vendor "Cisco" for product "Web Security Appliance" and version "11.8.0-453" | - |
Affected
| ||||||
Cisco Search vendor "Cisco" | Asyncos Search vendor "Cisco" for product "Asyncos" | >= 11.8.0 < 12.0.3-005 Search vendor "Cisco" for product "Asyncos" and version " >= 11.8.0 < 12.0.3-005" | - |
Affected
| ||||||
Cisco Search vendor "Cisco" | Asyncos Search vendor "Cisco" for product "Asyncos" | >= 12.5.0 < 12.5.2 Search vendor "Cisco" for product "Asyncos" and version " >= 12.5.0 < 12.5.2" | - |
Affected
|