Логотип exploitDog
bind:CVE-2021-1461
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2021-1461

Количество 3

Количество 3

nvd логотип

CVE-2021-1461

около 1 года назад

A vulnerability in the Image Signature Verification feature of Cisco SD-WAN Software could allow an authenticated, remote attacker with Administrator-level credentials to install a malicious software patch on an affected device. The vulnerability is due to improper verification of digital signatures for patch images. An attacker could exploit this vulnerability by crafting an unsigned software patch to bypass signature checks and loading it on an affected device. A successful exploit could allow the attacker to boot a malicious software patch image.Cisco has released software updates that address the vulnerability described in this advisory. There are no workarounds that address this vulnerability.

CVSS3: 4.9
EPSS: Низкий
github логотип

GHSA-pv55-c55f-33qw

около 1 года назад

A vulnerability in the Image Signature Verification feature of Cisco SD-WAN Software could allow an authenticated, remote attacker with Administrator-level credentials to install a malicious software patch on an affected device. The vulnerability is due to improper verification of digital signatures for patch images. An attacker could exploit this vulnerability by crafting an unsigned software patch to bypass signature checks and loading it on an affected device. A successful exploit could allow the attacker to boot a malicious software patch image.Cisco has released software updates that address the vulnerability described in this advisory. There are no workarounds that address this vulnerability.

CVSS3: 4.9
EPSS: Низкий
fstec логотип

BDU:2021-01227

почти 5 лет назад

Уязвимость функции проверки подписи образа микропрограммного обеспечения маршрутизаторов Cisco SD-WAN vEdge Routers, централизованной системой управления сетью Cisco SD-WAN vManage, позволяющая нарушителю оказать воздействие на целостность защищаемой информации

CVSS3: 4.9
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2021-1461

A vulnerability in the Image Signature Verification feature of Cisco SD-WAN Software could allow an authenticated, remote attacker with Administrator-level credentials to install a malicious software patch on an affected device. The vulnerability is due to improper verification of digital signatures for patch images. An attacker could exploit this vulnerability by crafting an unsigned software patch to bypass signature checks and loading it on an affected device. A successful exploit could allow the attacker to boot a malicious software patch image.Cisco has released software updates that address the vulnerability described in this advisory. There are no workarounds that address this vulnerability.

CVSS3: 4.9
0%
Низкий
около 1 года назад
github логотип
GHSA-pv55-c55f-33qw

A vulnerability in the Image Signature Verification feature of Cisco SD-WAN Software could allow an authenticated, remote attacker with Administrator-level credentials to install a malicious software patch on an affected device. The vulnerability is due to improper verification of digital signatures for patch images. An attacker could exploit this vulnerability by crafting an unsigned software patch to bypass signature checks and loading it on an affected device. A successful exploit could allow the attacker to boot a malicious software patch image.Cisco has released software updates that address the vulnerability described in this advisory. There are no workarounds that address this vulnerability.

CVSS3: 4.9
0%
Низкий
около 1 года назад
fstec логотип
BDU:2021-01227

Уязвимость функции проверки подписи образа микропрограммного обеспечения маршрутизаторов Cisco SD-WAN vEdge Routers, централизованной системой управления сетью Cisco SD-WAN vManage, позволяющая нарушителю оказать воздействие на целостность защищаемой информации

CVSS3: 4.9
0%
Низкий
почти 5 лет назад

Уязвимостей на страницу