Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2021-1359

A vulnerability in the configuration management of Cisco AsyncOS for Cisco Web Security Appliance (WSA) could allow an authenticated, remote attacker to perform command injection and elevate privileges to root. This vulnerability is due to insufficient validation of user-supplied XML input for the web interface. An attacker could exploit this vulnerability by uploading crafted XML configuration files that contain scripting code to a vulnerable device. A successful exploit could allow the attacker to execute arbitrary commands on the underlying operating system and elevate privileges to root. An attacker would need a valid user account with the rights to upload configuration files to exploit this vulnerability.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.009
EPSS Ranking 74.9%
CVSS Severity
CVSS v3 Score 6.3
CVSS v2 Score 9.0
Products affected by CVE-2021-1359
  • Cisco » Web Security Appliance » Version: 11.8.0-429
    cpe:2.3:a:cisco:web_security_appliance:11.8.0-429
  • Cisco » Web Security Appliance » Version: 11.8.0-453
    cpe:2.3:a:cisco:web_security_appliance:11.8.0-453
  • Cisco » Asyncos » Version: 11.8.0
    cpe:2.3:o:cisco:asyncos:11.8.0
  • Cisco » Asyncos » Version: 11.8.0-414
    cpe:2.3:o:cisco:asyncos:11.8.0-414
  • Cisco » Asyncos » Version: 11.8.1-023
    cpe:2.3:o:cisco:asyncos:11.8.1-023
  • Cisco » Asyncos » Version: 11.8.2-009
    cpe:2.3:o:cisco:asyncos:11.8.2-009
  • Cisco » Asyncos » Version: 11.8.3-018
    cpe:2.3:o:cisco:asyncos:11.8.3-018
  • Cisco » Asyncos » Version: 11.8.3-021
    cpe:2.3:o:cisco:asyncos:11.8.3-021
  • Cisco » Asyncos » Version: 12.0
    cpe:2.3:o:cisco:asyncos:12.0
  • Cisco » Asyncos » Version: 12.0.0
    cpe:2.3:o:cisco:asyncos:12.0.0
  • Cisco » Asyncos » Version: 12.0.1-268
    cpe:2.3:o:cisco:asyncos:12.0.1-268
  • Cisco » Asyncos » Version: 12.0.2
    cpe:2.3:o:cisco:asyncos:12.0.2
  • Cisco » Asyncos » Version: 12.5.0
    cpe:2.3:o:cisco:asyncos:12.5.0
  • Cisco » Asyncos » Version: 12.5.0-059
    cpe:2.3:o:cisco:asyncos:12.5.0-059
  • Cisco » Asyncos » Version: 12.5.0-633
    cpe:2.3:o:cisco:asyncos:12.5.0-633
  • Cisco » Asyncos » Version: 12.5.1-011
    cpe:2.3:o:cisco:asyncos:12.5.1-011


Contact Us

Shodan ® - All rights reserved