CVE-2021-1539
Published on: 06/04/2021 12:00:00 AM UTC
Last Modified on: 06/14/2021 06:36:00 PM UTC
CVE-2021-1539 - advisory for cisco-sa-asr5k-autho-bypass-mJDF5S7n
Source: Mitre Source: NIST CVE.ORG Print: PDF
Certain versions of Asr 5000 from Cisco contain the following vulnerability:
Multiple vulnerabilities in the authorization process of Cisco ASR 5000 Series Software (StarOS) could allow an authenticated, remote attacker to bypass authorization and execute a subset of CLI commands on an affected device. For more information about these vulnerabilities, see the Details section of this advisory.
- CVE-2021-1539 has been assigned by
[email protected] to track the vulnerability - currently rated as HIGH severity.
- The Cisco Product Security Incident Response Team (PSIRT) is not aware of any public announcements or malicious use of the vulnerabilities that are described in this advisory.
- Affected Vendor/Software:
Cisco - Cisco ASR 5000 Series Software version n/a
CVSS3 Score: 8.8 - HIGH
Attack Vector ⓘ |
Attack Complexity |
Privileges Required |
User Interaction |
---|---|---|---|
NETWORK | LOW | LOW | NONE |
Scope | Confidentiality Impact |
Integrity Impact |
Availability Impact |
UNCHANGED | HIGH | HIGH | HIGH |
CVSS2 Score: 6.5 - MEDIUM
Access Vector ⓘ |
Access Complexity |
Authentication |
---|---|---|
NETWORK | LOW | SINGLE |
Confidentiality Impact |
Integrity Impact |
Availability Impact |
PARTIAL | PARTIAL | PARTIAL |
CVE References
Description | Tags ⓘ | Link |
---|---|---|
Cisco ASR 5000 Series Software Authorization Bypass Vulnerabilities | tools.cisco.com text/html |
![]() |
There are currently no QIDs associated with this CVE
Known Affected Configurations (CPE V2.3)
Type | Vendor | Product | Version | Update | Edition | Language |
---|---|---|---|---|---|---|
Hardware
| Cisco | Asr 5000 | - | All | All | All |
Hardware
| Cisco | Asr 5500 | - | All | All | All |
Hardware
| Cisco | Asr 5700 | - | All | All | All |
Operating System | Cisco | Staros | All | All | All | All |
Application | Cisco | Virtualized Packet Core | - | All | All | All |
- cpe:2.3:h:cisco:asr_5000:-:*:*:*:*:*:*:*:
- cpe:2.3:h:cisco:asr_5500:-:*:*:*:*:*:*:*:
- cpe:2.3:h:cisco:asr_5700:-:*:*:*:*:*:*:*:
- cpe:2.3:o:cisco:staros:*:*:*:*:*:*:*:*:
- cpe:2.3:a:cisco:virtualized_packet_core:-:*:*:*:*:*:*:*:
No vendor comments have been submitted for this CVE
Social Mentions
Source | Title | Posted (UTC) |
---|---|---|
![]() |
CVE-2021-1539 : Multiple vulnerabilities in the authorization process of Cisco ASR 5000 Series Software StarOS co… twitter.com/i/web/status/1… | 2021-06-04 16:57:32 |
![]() |
CVE-2021-1539 | 2021-06-04 17:41:32 |