CVE-2021-1557
Cisco DNA Spaces Connector Privilege Escalation Vulnerabilities
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Multiple vulnerabilities in Cisco DNA Spaces Connector could allow an authenticated, local attacker to elevate privileges and execute arbitrary commands on the underlying operating system as root. These vulnerabilities are due to insufficient restrictions during the execution of affected CLI commands. An attacker could exploit these vulnerabilities by leveraging the insufficient restrictions during execution of these commands. A successful exploit could allow the attacker to elevate privileges from dnasadmin and execute arbitrary commands on the underlying operating system as root.
Múltiples vulnerabilidades en Cisco DNA Spaces Connector podrían permitir a un atacante local autenticado elevar privilegios y ejecutar comandos arbitrarios en el sistema operativo subyacente como root. Estas vulnerabilidades son debido a restricciones insuficientes durante la ejecución de comandos de CLI afectados. Un atacante podría explotar estas vulnerabilidades al aprovechar las restricciones insuficientes durante la ejecución de estos comandos. Una explotación con éxito podría permitir al atacante elevar privilegios de dnasadmin y ejecutar comandos arbitrarios en el sistema operativo subyacente como root
CVSS Scores
SSVC
- Decision:Track*
Timeline
- 2020-11-13 CVE Reserved
- 2021-05-22 CVE Published
- 2023-03-08 EPSS Updated
- 2024-11-08 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Cisco Search vendor "Cisco" | Dna Spaces: Connector Search vendor "Cisco" for product "Dna Spaces: Connector" | < 2.3.1 Search vendor "Cisco" for product "Dna Spaces: Connector" and version " < 2.3.1" | - |
Affected
|