SB2021032914 - Privilege escalation in Cisco IOS and IOS XE
Published: March 29, 2021
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Active Debug Code (CVE-ID: CVE-2021-1391)
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to the presence of development testing and verification scripts that remained on the device in the dragonite debugger. A local administrator can bypass the consent token mechanism with the residual scripts on the affected device and escalate from privilege level 15 to root privilege.
Remediation
Install update from vendor's website.