CVE-2021-1488
בינונית 6.7
תיאור (מקור, אנגלית)
A vulnerability in the upgrade process of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker to inject commands that could be executed with root privileges on the underlying operating system (OS). This vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by uploading a crafted upgrade package file to an affected device. A successful exploit could allow the attacker to inject commands that could be executed with root privileges on the underlying OS.
מדדים
- CVSS 3.1
-
6.7 (MEDIUM)
מקור הציון: NVD
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H - EPSS — סבירות ניצול
- 0% (אחוזון 000) נכון ל-15/8/2026
- CWE
- CWE-77, CWE-78
מוצרים מושפעים
cisco: secure firewall threat defense; cisco: adaptive security appliance software; cisco: firepower 1010; cisco: firepower 1120; cisco: firepower 1140; cisco: firepower 1150; cisco: firepower 2110; cisco: firepower 2120; cisco: firepower 2130; cisco: firepower 2140