Cisco IOS XE Software Web UI Command Injection (cisco-sa-iosxe-webcmdinjsh-UFJxTgZD)

high Nessus Plugin ID 148103

Synopsis

The remote device is missing a vendor-supplied security patch

Description

According to its self-reported version, Cisco IOS-XE Software is affected by a vulnerability. Please see the included Cisco BIDs and Cisco Security Advisory for more information.

Solution

Upgrade to the relevant fixed version referenced in Cisco bug ID CSCvq32553

See Also

http://www.nessus.org/u?7e57305e

https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvq32553

Plugin Details

Severity: High

ID: 148103

File Name: cisco-sa-iosxe-webcmdinjsh-UFJxTgZD-iosxe.nasl

Version: 1.6

Type: local

Family: CISCO

Published: 3/25/2021

Updated: 10/19/2023

Supported Sensors: Nessus

Risk Information

VPR

Risk Factor: High

Score: 7.4

CVSS v2

Risk Factor: High

Base Score: 9

Temporal Score: 7.4

Vector: CVSS2#AV:N/AC:L/Au:S/C:C/I:C/A:C

CVSS Score Source: CVE-2021-1435

CVSS v3

Risk Factor: High

Base Score: 7.2

Temporal Score: 6.7

Vector: CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:F/RL:O/RC:C

Vulnerability Information

CPE: cpe:/o:cisco:ios_xe

Required KB Items: Host/Cisco/IOS-XE/Version

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 3/24/2021

Vulnerability Publication Date: 3/24/2021

CISA Known Exploited Vulnerability Due Dates: 11/9/2023

Reference Information

CVE: CVE-2021-1435