Vulnerabilities > CVE-2021-1423 - Exposure of Resource to Wrong Sphere vulnerability in Cisco products

047910
CVSS 4.4 - MEDIUM
Attack vector
LOCAL
Attack complexity
LOW
Privileges required
HIGH
Confidentiality impact
NONE
Integrity impact
HIGH
Availability impact
NONE
local
low complexity
cisco
CWE-668

Summary

A vulnerability in the implementation of a CLI command in Cisco Aironet Access Points (AP) could allow an authenticated, local attacker to overwrite files in the flash memory of the device. This vulnerability is due to insufficient input validation for a specific command. An attacker could exploit this vulnerability by issuing a command with crafted arguments. A successful exploit could allow the attacker to overwrite or create files with data that is already present in other files that are hosted on the affected device.

Vulnerable Configurations

Part Description Count
Application
Cisco
37
Hardware
Cisco
11
OS
Cisco
4

Common Weakness Enumeration (CWE)