CVE-2021-34746
A vulnerability in the TACACS+ authentication, authorization and accounting (AAA) feature of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an unauthenticated, remote attacker to bypass authentication and log in to an affected device…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 17.7%, higher than 97% of all known CVEs. Patch or mitigate before the next change window.
Description
A vulnerability in the TACACS+ authentication, authorization and accounting (AAA) feature of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an unauthenticated, remote attacker to bypass authentication and log in to an affected device as an administrator. This vulnerability is due to incomplete validation of user-supplied input that is passed to an authentication script. An attacker could exploit this vulnerability by injecting parameters into an authentication request. A successful exploit could allow the attacker to bypass authentication and log in as an administrator to the affected device.
- CVSS 3.1
- 9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 17.66% probability · 97th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-289, CWE-287
- Affected
- cisco/enterprise nfv infrastructure software
- Source
- psirt@cisco.com
References
- https://github.com/orangecertcc/security-research/security/advisories/GHSA-gqx8-c4xr-c664Exploit, Third Party Advisory
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-nfvis-g2DMVVhVendor Advisory
- https://github.com/orangecertcc/security-research/security/advisories/GHSA-gqx8-c4xr-c664Exploit, Third Party Advisory
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-nfvis-g2DMVVhVendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.