Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2021-1560

Опубликовано: 22 мая 2021
Источник: nvd
CVSS3: 6.5
CVSS3: 7.2
CVSS2: 9
EPSS Низкий

Описание

Multiple vulnerabilities in Cisco DNA Spaces Connector could allow an authenticated, remote attacker to perform a command injection attack on an affected device. These vulnerabilities are due to insufficient input sanitization when executing affected commands. A high-privileged attacker could exploit these vulnerabilities on a Cisco DNA Spaces Connector by injecting crafted input during command execution. A successful exploit could allow the attacker to execute arbitrary commands as root within the Connector docker container.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:cisco:dna_spaces\:_connector:*:*:*:*:*:*:*:*
Версия до 2.0.519 (исключая)

EPSS

Процентиль: 87%
0.03425
Низкий

6.5 Medium

CVSS3

7.2 High

CVSS3

9 Critical

CVSS2

Дефекты

CWE-78
CWE-77

Связанные уязвимости

CVSS3: 7.2
github
больше 3 лет назад

Multiple vulnerabilities in Cisco DNA Spaces Connector could allow an authenticated, remote attacker to perform a command injection attack on an affected device. These vulnerabilities are due to insufficient input sanitization when executing affected commands. A high-privileged attacker could exploit these vulnerabilities on a Cisco DNA Spaces Connector by injecting crafted input during command execution. A successful exploit could allow the attacker to execute arbitrary commands as root within the Connector docker container.

CVSS3: 6.5
fstec
больше 4 лет назад

Уязвимость приложения сбора и агрегации данных из контроллеров и точек доступа Cisco DNA Spaces Connector, связанная с внедрением или модификацией аргумента, позволяющая нарушителю выполнять произвольные команды с привилегиями root

EPSS

Процентиль: 87%
0.03425
Низкий

6.5 Medium

CVSS3

7.2 High

CVSS3

9 Critical

CVSS2

Дефекты

CWE-78
CWE-77