CVE-2021-1423
Summary
| CVE | CVE-2021-1423 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-03-24 21:15:00 UTC |
| Updated | 2023-11-07 03:28:00 UTC |
| Description | A vulnerability in the implementation of a CLI command in Cisco Aironet Access Points (AP) could allow an authenticated, local attacker to overwrite files in the flash memory of the device. This vulnerability is due to insufficient input validation for a specific command. An attacker could exploit this vulnerability by issuing a command with crafted arguments. A successful exploit could allow the attacker to overwrite or create files with data that is already present in other files that are hosted on the affected device. |
Risk And Classification
Problem Types: CWE-668
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Cisco | 1100 Integrated Services Router | - | All | All | All |
| Hardware | Cisco | Aironet 1540 | - | All | All | All |
| Hardware | Cisco | Aironet 1560 | - | All | All | All |
| Hardware | Cisco | Aironet 1800 | - | All | All | All |
| Hardware | Cisco | Aironet 2800 | - | All | All | All |
| Hardware | Cisco | Aironet 3800 | - | All | All | All |
| Hardware | Cisco | Aironet 4800 | - | All | All | All |
| Application | Cisco | Aironet Access Point Software | - | All | All | All |
| Hardware | Cisco | Catalyst 9100 | - | All | All | All |
| Hardware | Cisco | Catalyst 9800 | - | All | All | All |
| Operating System | Cisco | Catalyst 9800 Firmware | All | All | All | All |
| Operating System | Cisco | Catalyst 9800 Firmware | All | All | All | All |
| Hardware | Cisco | Catalyst Iw6300 | - | All | All | All |
| Hardware | Cisco | Esw6300 | - | All | All | All |
| Hardware | Cisco | Isr 1100 | - | All | All | All |
| Application | Cisco | Wireless Lan Controller Software | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Cisco Aironet Access Points Arbitrary File Overwrite Vulnerability | CISCO | tools.cisco.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.