SB2021032912 - Active Debug Code in Cisco IOS XE 



SB2021032912 - Active Debug Code in Cisco IOS XE

Published: March 29, 2021

Security Bulletin ID SB2021032912
Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Physical access
Highest impact Code execution

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Active Debug Code (CVE-ID: CVE-2021-1398)

The vulnerability allows a local attacker to execute arbitrary code on the system.

The vulnerability exists due to incorrect validations of specific function arguments that are passed to the boot script. An attacker with physical access can tamper with a specific file, execute unsigned code at boot time and bypass the image verification check in the secure boot process of the affected device.


Remediation

Install update from vendor's website.