CVE-2021-1528
Estado: ModificadaAlta (7.8)—
A vulnerability in the CLI of Cisco SD-WAN Software could allow an authenticated, local attacker to gain elevated privileges on an affected system. This vulnerability exists because the affected software does not properly restrict access to privileged processes. An attacker could exploit this vulnerability by invoking a privileged process in the affected system. A successful exploit could allow the attacker to perform actions with the privileges of the root user.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Puntuación base: 7.8
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.25%
- Percentil entre todas las CVEs puntuadas: 15
- Fecha de la puntuación: 4/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (11)
Cisco — Catalyst Sd-wan ManagerCisco — Sd-wan Vbond OrchestratorCisco — Vedge 1000 FirmwareCisco — Vedge 100 FirmwareCisco — Vedge 100b FirmwareCisco — Vedge 100m FirmwareCisco — Vedge 100wm FirmwareCisco — Vedge 2000 FirmwareCisco — Vedge 5000 FirmwareCisco — Vedge Cloud FirmwareCisco — Vsmart Controller
CWE
- CWE-250
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2021-1528",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2021-1528",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "total"
}
],
"version": "2.0.3",
"timestamp": "2024-11-07T21:43:49.366641Z"
}
}
],
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 7.2,
"accessVector": "LOCAL",
"vectorString": "AV:L/AC:L/Au:N/C:C/I:C/A:C",
"authentication": "NONE",
"integrityImpact": "COMPLETE",
"accessComplexity": "LOW",
"availabilityImpact": "COMPLETE",
"confidentialityImpact": "COMPLETE"
},
"acInsufInfo": false,
"impactScore": 10,
"baseSeverity": "HIGH",
"obtainAllPrivilege": false,
"exploitabilityScore": 3.9,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "psirt@cisco.com",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 7.8,
"attackVector": "LOCAL",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "LOW",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 1.8
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 7.8,
"attackVector": "LOCAL",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "LOW",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 1.8
}
]
},
"affected": [
{
"source": "psirt@cisco.com",
"affectedData": [
{
"vendor": "Cisco",
"product": "Cisco SD-WAN Solution",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2021-06-04T17:15:09.020",
"references": [
{
"url": "https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sd-wan-fuErCWwF",
"tags": [
"Vendor Advisory"
],
"source": "psirt@cisco.com"
},
{
"url": "https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sd-wan-fuErCWwF",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Secondary",
"source": "psirt@cisco.com",
"description": [
{
"lang": "en",
"value": "CWE-250"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "A vulnerability in the CLI of Cisco SD-WAN Software could allow an authenticated, local attacker to gain elevated privileges on an affected system. This vulnerability exists because the affected software does not properly restrict access to privileged processes. An attacker could exploit this vulnerability by invoking a privileged process in the affected system. A successful exploit could allow the attacker to perform actions with the privileges of the root user."
},
{
"lang": "es",
"value": "Una vulnerabilidad en la CLI del Software Cisco SD-WAN, podría permitir a un atacante local autenticado alcanzar privilegios elevados en un sistema afectado. Esta vulnerabilidad se presenta porque el software afectado no restringe apropiadamente el acceso a los procesos con privilegios. Un atacante podría explotar esta vulnerabilidad al invocar un proceso privilegiado en el sistema afectado. Una explotación con éxito podría permitir al atacante llevar a cabo acciones con los privilegios del usuario root"
}
],
"lastModified": "2026-06-17T03:31:59.353",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:cisco:catalyst_sd-wan_manager:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "0ABABC6A-BE28-4107-A00F-E6D8841168F5",
"versionEndExcluding": "20.4.2",
"versionStartIncluding": "20.4"
},
{
"criteria": "cpe:2.3:a:cisco:catalyst_sd-wan_manager:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "BE2C4782-DD4D-4113-A367-13DA609AD5F4",
"versionEndExcluding": "20.5.1",
"versionStartIncluding": "20.5"
},
{
"criteria": "cpe:2.3:a:cisco:sd-wan_vbond_orchestrator:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "C8099190-F1EC-4AFC-9607-5F13E09B7C26",
"versionEndExcluding": "20.4.2",
"versionStartIncluding": "20.4"
},
{
"criteria": "cpe:2.3:a:cisco:sd-wan_vbond_orchestrator:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "3079495E-BB87-48EF-92F2-5C0DFBBDFB2D",
"versionEndExcluding": "20.5.1",
"versionStartIncluding": "20.5"
}
],
"operator": "OR"
}
]
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:cisco:vsmart_controller:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "A234D95C-0AC1-4183-8457-550932E10B7E",
"versionEndExcluding": "20.4.2",
"versionStartIncluding": "20.4"
},
{
"criteria": "cpe:2.3:a:cisco:vsmart_controller:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "9E3634B4-6146-4DF5-B242-6606F6CCBA00",
"versionEndExcluding": "20.5.1",
"versionStartIncluding": "20.5"
}
],
"operator": "OR"
}
]
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:cisco:vedge_100_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "4E75BF8E-8BA5-4A53-9CE9-F10CC245FFC3",
"versionEndExcluding": "20.4.2",
"versionStartIncluding": "20.4"
},
{
"criteria": "cpe:2.3:o:cisco:vedge_100_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "B89D5AE2-3ED3-4C57-AF93-E9750D38F029",
"versionEndExcluding": "20.5.1",
"versionStartIncluding": "20.5"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:cisco:vedge_100:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "00AAB4DD-1C45-412F-84AA-C056A0BBFB9A"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:cisco:vedge_1000_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "6916F5F8-4E5B-4878-9C08-430F30EB61FD",
"versionEndExcluding": "20.4.2",
"versionStartIncluding": "20.4"
},
{
"criteria": "cpe:2.3:o:cisco:vedge_1000_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "834192CC-585D-445E-B2AD-D73E9CDF3FED",
"versionEndExcluding": "20.5.1",
"versionStartIncluding": "20.5"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:cisco:vedge_1000:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "F019975D-3A45-4522-9CB9-F4258C371DF6"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:cisco:vedge_100b_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "1D0C212A-DDCE-4D44-8D2A-8A7DEC4C30E2",
"versionEndExcluding": "20.4.2",
"versionStartIncluding": "20.4"
},
{
"criteria": "cpe:2.3:o:cisco:vedge_100b_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "632EBFCA-132A-4AC9-A244-7D6EBCAEAC16",
"versionEndExcluding": "20.5.1",
"versionStartIncluding": "20.5"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:cisco:vedge_100b:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "0811E0B5-889E-451E-B754-A8FEE32BDFA2"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:cisco:vedge_100m_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "C7B4CFA5-743E-4A04-9FED-CB9A5F587192",
"versionEndExcluding": "20.4.2",
"versionStartIncluding": "20.4"
},
{
"criteria": "cpe:2.3:o:cisco:vedge_100m_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "6375DFCF-2EEB-482B-AAD4-8FAB8F03C9C0",
"versionEndExcluding": "20.5.1",
"versionStartIncluding": "20.5"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:cisco:vedge_100m:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "36973815-F46D-4ADA-B9DF-BCB70AC60BD3"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:cisco:vedge_100wm_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "DA09C6C5-B770-4C42-8DE0-4482D7FC5512",
"versionEndExcluding": "20.4.2",
"versionStartIncluding": "20.4"
},
{
"criteria": "cpe:2.3:o:cisco:vedge_100wm_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "104BBAE4-C7C1-4E5A-A540-AF679FCE1CD2",
"versionEndExcluding": "20.5.1",
"versionStartIncluding": "20.5"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:cisco:vedge_100wm:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "061A302C-8D35-4E80-93DA-916DA7E90C06"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:cisco:vedge_2000_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "E609583F-9F2E-435A-88A3-77950F3825BD",
"versionEndExcluding": "20.4.2",
"versionStartIncluding": "20.4"
},
{
"criteria": "cpe:2.3:o:cisco:vedge_2000_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "584863D2-B181-4CDF-8266-EEBA56A5AA85",
"versionEndExcluding": "20.5.1",
"versionStartIncluding": "20.5"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:cisco:vedge_2000:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "140AF13E-4463-478B-AA94-97406A80CB86"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:cisco:vedge_5000_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "39F5B972-D194-4333-BEF6-129BEBB61E9E",
"versionEndExcluding": "20.4.2",
"versionStartIncluding": "20.4"
},
{
"criteria": "cpe:2.3:o:cisco:vedge_5000_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "50C0D971-E2C4-4048-A08F-0A5D437866F8",
"versionEndExcluding": "20.5.1",
"versionStartIncluding": "20.5"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:cisco:vedge_5000:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "1356861D-E6CA-4973-9597-629507E8C07E"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:cisco:vedge_100b_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "1D0C212A-DDCE-4D44-8D2A-8A7DEC4C30E2",
"versionEndExcluding": "20.4.2",
"versionStartIncluding": "20.4"
},
{
"criteria": "cpe:2.3:o:cisco:vedge_100b_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "632EBFCA-132A-4AC9-A244-7D6EBCAEAC16",
"versionEndExcluding": "20.5.1",
"versionStartIncluding": "20.5"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:cisco:vedge_100b:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "0811E0B5-889E-451E-B754-A8FEE32BDFA2"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:cisco:vedge_cloud_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "E8696F30-DB2C-46D8-99BF-68A3D3AC0988",
"versionEndExcluding": "20.4.2",
"versionStartIncluding": "20.4"
},
{
"criteria": "cpe:2.3:o:cisco:vedge_cloud_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "DDBBDE43-BBAE-431B-AF56-73D9CC8743F7",
"versionEndExcluding": "20.5.1",
"versionStartIncluding": "20.5"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:cisco:vedge_cloud:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "94999112-9EAA-4707-B002-F867D7628C49"
}
],
"operator": "OR"
}
],
"operator": "AND"
}
],
"sourceIdentifier": "psirt@cisco.com"
}