CVE-2021-1539

Description

Multiple vulnerabilities in the authorization process of Cisco ASR 5000 Series Software (StarOS) could allow an authenticated, remote attacker to bypass authorization and execute a subset of CLI commands on an affected device. For more information about these vulnerabilities, see the Details section of this advisory.

Risk Information

Base Score
8.8
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
0.285

Associated Vulnerability

VulnerabilityOS Platform
Cisco ASR 5000 Series Software Authorization Bypass Vulnerabilities For Cisco PGW Packet Data Network GatewayNCM
Cisco ASR 5000 Series Software Authorization Bypass Vulnerabilities For Cisco ASR 5000 SeriesNCM
CVE-2021-1539NCM

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-1705563Security Update for Cisco PGW Packet Data Network Gateway 17.0.E0.55671
PATCH-1706032Security Update for Cisco ASR 5000 Series 21.3.A0.66703

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234