CVE-2021-1432(cisco / ios_xe)

LOWCVSS 7.3 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A vulnerability in the CLI of Cisco IOS XE SD-WAN Software could allow an authenticated, local attacker to execute arbitrary commands on the underlying operating system as the root user. The attacker must be authenticated on the affected device as a low-privileged user to exploit this vulnerability. This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by injecting arbitrary commands to a file as a lower-privileged user. The commands are then executed on the device by the root user. A successful exploit could allow the attacker to execute arbitrary commands as the root user.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-20CWE-74

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • ios_xe
  • ios_xe_sd-wan

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • 1 total mentions across 1 day

Affected systems

Vendors
Products
ios_xeios_xe_sd-wan

26 versions affected across 2 products

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-10-07: 110-07
Full discourse1 post
  • DFIR Lab@DFIR_Lab

    🚨 HIGH Severity: CVE-2021-1432 (CVSS 7.3) Cisco IOS XE SD-WAN CLI vulnerability allows authenticated local attackers to execute arbitrary commands as root via command injection. Affected: Cisco IOS XE SD-WAN Software Patch immediately. #CVE #Vulnerability #PatchNow https://t.co/Og4Hzb74pS

    000003
    143 followersView on X
CPE platform detail26 entries

26 of 26 entries

PartVendorProductVersionTarget SWTarget HW
OSciscoios_xe16.12.1--
OSciscoios_xe16.12.1a--
OSciscoios_xe16.12.1c--
OSciscoios_xe16.12.1s--
OSciscoios_xe16.12.1t--
OSciscoios_xe16.12.1w--
OSciscoios_xe16.12.1x--
OSciscoios_xe16.12.1y--
OSciscoios_xe16.12.1z--
OSciscoios_xe16.12.1za--
OSciscoios_xe16.12.2--
OSciscoios_xe16.12.2a--
OSciscoios_xe16.12.2s--
OSciscoios_xe16.12.2t--
OSciscoios_xe16.12.3--
OSciscoios_xe16.12.3a--
OSciscoios_xe16.12.3s--
OSciscoios_xe16.12.4--
OSciscoios_xe16.12.4a--
OSciscoios_xe17.2.1--
OSciscoios_xe17.2.1a--
OSciscoios_xe17.2.1r--
OSciscoios_xe17.2.1v--
OSciscoios_xe3.15.1xbs--
OSciscoios_xe3.15.2xbs--
OSciscoios_xe_sd-wan---

Explore more