CVE-2021-1539

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
04/06/2021
Last modified:
07/11/2023

Description

Multiple vulnerabilities in the authorization process of Cisco ASR 5000 Series Software (StarOS) could allow an authenticated, remote attacker to bypass authorization and execute a subset of CLI commands on an affected device. For more information about these vulnerabilities, see the Details section of this advisory.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:cisco:staros:*:*:*:*:*:*:*:* 21.16.9 (excluding)
cpe:2.3:o:cisco:staros:*:*:*:*:*:*:*:* 21.17.0 (including) 21.17.10 (excluding)
cpe:2.3:o:cisco:staros:*:*:*:*:*:*:*:* 21.18.0 (including) 21.18.16 (excluding)
cpe:2.3:o:cisco:staros:*:*:*:*:*:*:*:* 21.19.0 (including) 21.19.11 (excluding)
cpe:2.3:o:cisco:staros:*:*:*:*:*:*:*:* 21.19.n (including) 21.19.n7 (excluding)
cpe:2.3:o:cisco:staros:*:*:*:*:*:*:*:* 21.20.0 (including) 21.20.8 (excluding)
cpe:2.3:h:cisco:asr_5000:-:*:*:*:*:*:*:*
cpe:2.3:h:cisco:asr_5500:-:*:*:*:*:*:*:*
cpe:2.3:h:cisco:asr_5700:-:*:*:*:*:*:*:*
cpe:2.3:a:cisco:virtualized_packet_core:-:*:*:*:*:*:*:*