HIGH✓ PATCH🇵🇱 Wersja polska

CVE-2021-1437

CVSS 7.5v3.1pub. 2021-03-24upd. 2024-11-21

A vulnerability in the FlexConnect Upgrade feature of Cisco Aironet Series Access Points Software could allow an unauthenticated, remote attacker to obtain confidential information from an affected device. This vulnerability is due to an unrestricted Trivial File Transfer Protocol (TFTP) configuration. An attacker could exploit this vulnerability by sending a specific TFTP request to an affected device. A successful exploit could allow the attacker to download any file from the filesystem of the affected access point (AP).

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
  • Cisco 1100 Integrated Services Router

    HW
    Cisco
    all versions
  • Cisco Aironet 1540

    HW
    Cisco
    all versions
  • Cisco Aironet 1560

    HW
    Cisco
    all versions
  • Cisco Aironet 1800

    HW
    Cisco
    all versions
  • Cisco Aironet 2800

    HW
    Cisco
    all versions
  • Cisco Aironet 3800

    HW
    Cisco
    all versions
  • Cisco Aironet 4800

    HW
    Cisco
    all versions
  • Cisco Aironet Access Point Software

    APP
    Cisco
    all versions
  • Cisco Catalyst 9100

    HW
    Cisco
    all versions
  • Cisco Catalyst 9800

    HW
    Cisco
    all versions
  • Cisco Catalyst 9800 Firmware

    OS
    Cisco
    17.1 – 17.3.3 (excl.)
  • Cisco Catalyst Iw6300

    HW
    Cisco
    all versions
  • Cisco Esw6300

    HW
    Cisco
    all versions
  • Cisco Wireless Lan Controller Software

    APP
    Cisco
    8.10.112.0 – 8.10.142.0 (excl.)
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
CWE
References

Related vulnerabilities

CVE-2017-12240CRITICAL9.8⚠ KEVPL ✓same product

Buffer overflow w DHCP relay Cisco IOS — RCE bez uwierzytelnienia

CVE-2022-20695CRITICAL10.0PL ✓same product

Cisco WLC — pominięcie uwierzytelnienia przez management interface

CVE-2021-34770CRITICAL10.0PL ✓same product

RCE i DoS w obsłudze protokołu CAPWAP w Cisco IOS XE dla Catalyst 9000

CVE-2021-34727CRITICAL9.8PL ✓same product

Buffer overflow w procesie vDaemon Cisco IOS XE SD-WAN — RCE z uprawnieniami root

CVE-2019-15260CRITICAL9.8PL ✓same product

Cisco Aironet AP — nieautoryzowany dostęp z podwyższonymi uprawnieniami