SB2021032418 - Privilege escalation in Cisco IOS XE ROM Monitor
Published: March 24, 2021
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) OS Command Injection (CVE-ID: CVE-2021-1452)
The vulnerability allows a local user to execute arbitrary shell commands on the target system.
The vulnerability exists in ROM Monitor (ROMMON) due to incorrect validations of specific function arguments passed to a boot script when specific ROMMON variables are set.An attacker with physical access to the system can execute unsigned code at system boot time.
Remediation
Install update from vendor's website.