CVE detail

CVE-2021-1421 — CVE-2021-1421

Published 2021-05-06 · Modified 2026-06-17 · Vendor cisco · Product enterprise_nfv_infrastructure_software · Source nvd
HIGH
severity
CVSS-derived band
7.8
CVSS v3
0–10 scale
0.0067
EPSS probability
exploitation probability, 30d
49.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog

Description

A vulnerability in Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, local attacker to perform a command injection attack on an affected device. The vulnerability is due to insufficient validation of user-supplied input to a configuration command. An attacker could exploit this vulnerability by including malicious input during the execution of this command. A successful exploit could allow a non-privileged attacker authenticated in the restricted CLI to execute arbitrary commands on the underlying operating system (OS) with root privileges.

Remediation

ProductVulnerable rangeFixed versionAdvisory
Cisco Cisco Enterprise NFV Infrastructure Softwarenot specifiedadvisory ↗

References

cvedb.io · NVD · CISA KEV · FIRST EPSS · vendor advisories (CVE Program List v5). Informational only, no warranty — verify every remediation against the vendor advisory before acting on it. This product uses data from the NVD API but is not endorsed or certified by the NVD, CISA, FIRST.org or any vendor named. CVE® is a registered trademark of The MITRE Corporation.