CVE-2021-1560
Cisco DNA Spaces Connector Command Injection Vulnerabilities
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Multiple vulnerabilities in Cisco DNA Spaces Connector could allow an authenticated, remote attacker to perform a command injection attack on an affected device. These vulnerabilities are due to insufficient input sanitization when executing affected commands. A high-privileged attacker could exploit these vulnerabilities on a Cisco DNA Spaces Connector by injecting crafted input during command execution. A successful exploit could allow the attacker to execute arbitrary commands as root within the Connector docker container.
Múltiples vulnerabilidades en Cisco DNA Spaces Connector podrían permitir a un atacante remoto autenticado llevar a cabo un ataque de inyección de comandos en un dispositivo afectado. Estas vulnerabilidades son debido a un saneamiento insuficiente de entrada cuando se ejecutan comandos afectados. Un atacante muy privilegiado podría explotar estas vulnerabilidades en un Cisco DNA Spaces Connector al inyectar una entrada diseñada durante la ejecución del comando. Una explotación con éxito podría permitir al atacante ejecutar comandos arbitrarios como root dentro del Contenedor docker container
CVSS Scores
SSVC
- Decision:Track*
Timeline
- 2020-11-13 CVE Reserved
- 2021-05-22 CVE Published
- 2023-03-07 EPSS Updated
- 2024-11-08 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection')
- CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Cisco Search vendor "Cisco" | Dna Spaces: Connector Search vendor "Cisco" for product "Dna Spaces: Connector" | < 2.0.519 Search vendor "Cisco" for product "Dna Spaces: Connector" and version " < 2.0.519" | - |
Affected
|