CVE-2021-1546

moderate-risk
Published 2021-09-23

A vulnerability in the CLI of Cisco SD-WAN Software could allow an authenticated, local attacker to access sensitive information. This vulnerability is due to improper protections on file access through the CLI. An attacker could exploit this vulnerability by running a CLI command that targets an arbitrary file on the local system. A successful exploit could allow the attacker to return portions of an arbitrary file, possibly resulting in the disclosure of sensitive information.

Do I need to act?

-
0.15% chance of exploitation
EPSS score — low exploit probability
-
Not on CISA KEV list
No confirmed active exploitation reported to CISA
?
Patch status unknown
Check vendor advisories for fix availability and mitigation guidance
5
CVSS 5.5/10 Medium
LOCAL / LOW complexity

Affected Products (12)

Vsmart Controller Firmware
Vedge 100 Firmware
Vedge 1000 Firmware
Vedge 100B Firmware
Vedge 100M Firmware
Vedge 100Wm Firmware
Vedge 2000 Firmware
Vedge 5000 Firmware
Vedge Cloud Firmware

Affected Vendors

36
/ 100
moderate-risk
Severity 18/34 · Moderate
Exploitability 1/34 · Minimal
Exposure 17/34 · Moderate