← volver
CVE-2021-1299

Cisco SD-WAN Command Injection Vulnerabilities

CVSS 8.1 HIGHEPSS 2.4%CWE-20
Vexday Risk Score
21Bajo
Decisión SSVC (CISA)
Track
Sin señal de explotación → monitorear
CVSS 8.1EPSS 2.4%KEV nãoPoC Nuclei Metasploit Patch referenciado
Ciclo de vida
20 ene 2021Publicada en NVD
Recomendación: Monitorear — sin señal de explotación por ahora.
Multiple vulnerabilities in Cisco SD-WAN products could allow an authenticated attacker to perform command injection attacks against an affected device, which could allow the attacker to take certain actions with root privileges on the device. For more information about these vulnerabilities, see the Details section of this advisory.
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N

¿Quieres saber si tu infraestructura está expuesta a esto?

Hablar con TrueHacking →