CVE-2021-1398 - Active Debug Code

Severity

68%

Complexity

9%

Confidentiality

98%

A vulnerability in the boot logic of Cisco IOS XE Software could allow an authenticated, local attacker with level 15 privileges or an unauthenticated attacker with physical access to execute arbitrary code on the underlying Linux operating system of an affected device. This vulnerability is due to incorrect validations of specific function arguments that are passed to the boot script. An attacker could exploit this vulnerability by tampering with a specific file, which an affected device would process during the initial boot process. On systems that are protected by the Unified Extensible Firmware Interface (UEFI) secure boot feature, a successful exploit could allow the attacker to execute unsigned code at boot time and bypass the image verification check in the secure boot process of the affected device.

CVSS 3.1 Base Score 6.8. CVSS Attack Vector: physical. CVSS Attack Complexity: low. CVSS Vector: (CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

CVSS 2.0 Base Score 6.9. CVSS Attack Vector: local. CVSS Attack Complexity: medium. CVSS Vector: (AV:L/AC:M/Au:N/C:C/I:C/A:C).

Demo Examples

Active Debug Code

CWE-489

Debug code can be used to bypass authentication. For example, suppose an application has a login script that receives a username and a password. Assume also that a third, optional, parameter, called "debug", is interpreted by the script as requesting a switch to debug mode, and that when this parameter is given the username and password are not checked. In such a case, it is very simple to bypass the authentication process if the special behavior of the application regarding the debug parameter is known. In a case where the form is:


               
</FORM>
<INPUT TYPE=SUBMIT>

Then a conforming link will look like:


               
http://TARGET/authenticate_login.cgi?username=...&password=...

An attacker can change this to:


               
http://TARGET/authenticate_login.cgi?username=&password=&debug=1

Which will grant the attacker access to the site, bypassing the authentication process.

Overview

Type

Cisco IOS

First reported 3 years ago

2021-03-24 20:15:00

Last updated 3 years ago

2021-03-29 21:45:00

Affected Software

Cisco IOS XE 3.7.0BS

3.7.0bs

Cisco IOS XE 3.7.0s

3.7.0s

Cisco IOS XE 3.7.1s

3.7.1s

Cisco IOS XE 3.7.2s

3.7.2s

Cisco IOS XE 3.7.4AS

3.7.4as

Cisco IOS XE 3.7.8S

3.7.8s

Cisco IOS XE 3.8.0s

3.8.0s

Cisco IOS XE 3.8.1S

3.8.1s

Cisco IOS XE 3.8.2S

3.8.2s

Cisco IOS XE 3.9.0AS

3.9.0as

Cisco IOS XE 3.9.0s

3.9.0s

Cisco IOS XE 3.9.1AS

3.9.1as

Cisco IOS XE 3.9.1s

3.9.1s

Cisco IOS XE 3.9.2S

3.9.2s

Cisco IOS XE 3.10.0S

3.10.0s

Cisco IOS XE 3.10.1S

3.10.1s

Cisco IOS XE 3.10.1XBS

3.10.1xbs

Cisco IOS XE 3.10.2AS

3.10.2as

Cisco IOS XE 3.10.2S

3.10.2s

Cisco IOS XE 3.10.3S

3.10.3s

Cisco IOS XE 3.10.5S

3.10.5s

Cisco IOS XE 3.10.6S

3.10.6s

Cisco IOS XE 3.10.7S

3.10.7s

Cisco IOS XE 3.10.10S

3.10.10s

Cisco IOS XE 3.11.0S

3.11.0s

Cisco IOS XE 3.11.1S

3.11.1s

Cisco IOS XE 3.11.2S

3.11.2s

Cisco IOS XE 3.12.0AS

3.12.0as

Cisco IOS XE 3.13.3S

3.13.3s

Cisco IOS XE 3.13.6BS

3.13.6bs

Cisco IOS XE 3.13.10S

3.13.10s

Cisco IOS XE 3.14.0S

3.14.0s

Cisco IOS XE 3.14.1S

3.14.1s

Cisco IOS XE 3.14.2S

3.14.2s

Cisco IOS XE 3.14.3S

3.14.3s

Cisco IOS XE 3.14.4S

3.14.4s

Cisco IOS XE 3.15.1cS

3.15.1cs

Cisco IOS XE 3.15.4S

3.15.4s

Cisco IOS XE 3.16.0AS

3.16.0as

Cisco IOS XE 3.16.0BS

3.16.0bs

Cisco IOS XE 3.16.0cS

3.16.0cs

Cisco IOS XE 3.16.1AS

3.16.1as

Cisco IOS XE 3.16.1S

3.16.1s

Cisco IOS XE 3.16.2BS

3.16.2bs

Cisco IOS XE 3.16.4CS

3.16.4cs

Cisco IOS XE 3.16.4ES

3.16.4es

Cisco IOS XE 3.16.4GS

3.16.4gs

Cisco IOS XE 3.16.5AS

3.16.5as

Cisco IOS XE 3.16.5BS

3.16.5bs

Cisco IOS XE 3.16.7AS

3.16.7as

Cisco IOS XE 3.16.7BS

3.16.7bs

Cisco IOS XE 3.16.8S

3.16.8s

Cisco IOS XE 3.16.9S

3.16.9s

Cisco IOS XE 3.16.10S

3.16.10s

Cisco IOS XE 3.17.1AS

3.17.1as

Cisco IOS XE 3.17.2S

3.17.2s

Cisco IOS XE 3.18.0AS

3.18.0as

Cisco IOS XE 3.18.0S

3.18.0s

Cisco IOS XE 3.18.1GSP

3.18.1gsp

Cisco IOS XE 3.18.1HSP

3.18.1hsp

Cisco IOS XE 3.18.1ISP

3.18.1isp

Cisco IOS XE 3.18.3ASP

3.18.3asp

Cisco IOS XE 3.18.3BSP

3.18.3bsp

Cisco IOS XE 3.18.4S

3.18.4s

Cisco IOS XE 3.18.4SP

3.18.4sp

Cisco IOS XE 3.18.5SP

3.18.5sp

Cisco IOS XE 3.18.6SP

3.18.6sp

Cisco IOS XE 3.18.7SP

3.18.7sp

Cisco IOS XE 3.18.8SP

3.18.8sp

Cisco IOS XE 16.1.1

16.1.1

Cisco IOS XE 16.3.4

16.3.4

Cisco IOS XE 16.3.5

16.3.5

Cisco IOS XE 16.3.7

16.3.7

Cisco IOS XE 16.3.8

16.3.8

Cisco IOS XE 16.4.2

16.4.2

Cisco IOS XE 16.4.3

16.4.3

Cisco IOS XE 16.5.1

16.5.1

Cisco IOS XE 16.5.1B

16.5.1b

Cisco IOS XE 16.5.2

16.5.2

Cisco IOS XE 16.5.3

16.5.3

Cisco IOS XE 16.6.4

16.6.4

Cisco IOS XE 16.6.4A

16.6.4a

Cisco IOS XE 16.6.4S

16.6.4s

Cisco IOS XE 16.6.5A

16.6.5a

Cisco IOS XE 16.6.5B

16.6.5b

Cisco IOS XE 16.6.6

16.6.6

Cisco IOS XE 16.6.7A

16.6.7a

Cisco IOS XE 16.6.8

16.6.8

Cisco IOS XE 16.7.1A

16.7.1a

Cisco IOS XE 16.7.1B

16.7.1b

Cisco IOS XE 16.7.3

16.7.3

Cisco IOS XE 16.7.4

16.7.4

Cisco IOS XE 16.8.1A

16.8.1a

Cisco IOS XE 16.8.1B

16.8.1b

Cisco IOS XE 16.8.1C

16.8.1c

Cisco IOS XE 16.8.1D

16.8.1d

Cisco IOS XE 16.8.1E

16.8.1e

Cisco IOS XE 16.8.1S

16.8.1s

Cisco IOS XE 16.8.2

16.8.2

Cisco IOS XE 16.8.3

16.8.3

Cisco IOS XE16.9.1

16.9.1

Cisco IOS XE 16.9.1A

16.9.1a

Cisco IOS XE 16.9.1B

16.9.1b

Cisco IOS XE 16.9.1C

16.9.1c

Cisco IOS XE 16.9.1D

16.9.1d

Cisco IOS XE 16.9.1S

16.9.1s

Cisco IOS XE 16.9.2

16.9.2

Cisco IOS XE 16.9.2A

16.9.2a

Cisco IOS XE 16.9.2S

16.9.2s

Cisco IOS XE 16.9.3

16.9.3

Cisco IOS XE 16.9.3A

16.9.3a

Cisco IOS XE 16.9.3H

16.9.3h

Cisco IOS XE 16.9.3S

16.9.3s

Cisco IOS XE 16.9.4C

16.9.4c

Cisco IOS XE 16.9.5

16.9.5

Cisco IOS XE 16.9.5F

16.9.5f

Cisco IOS XE 16.10.1

16.10.1

Cisco IOS XE 16.10.1A

16.10.1a

Cisco IOS XE 16.10.1B

16.10.1b

Cisco IOS XE 16.10.1C

16.10.1c

Cisco IOS XE 16.10.1D

16.10.1d

Cisco IOS XE 16.10.1E

16.10.1e

Cisco IOS XE 16.10.1F

16.10.1f

Cisco IOS XE 16.10.1G

16.10.1g

Cisco IOS XE 16.10.1S

16.10.1s

Cisco IOS XE 16.10.2

16.10.2

Cisco IOS XE 16.10.3

16.10.3

Cisco IOS XE 16.11.1

16.11.1

Cisco IOS XE 16.12.1

16.12.1

Cisco IOS XE 16.12.1Y

16.12.1y

Cisco IOS XE 16.12.2

16.12.2

Cisco IOS XE 16.12.2A

16.12.2a

Cisco IOS XE 16.12.4

16.12.4

Cisco IOS XE 17.1.1

17.1.1

Stay updated

ExploitPedia is constantly evolving. Sign up to receive a notification when we release additional functionality.

Get in touch

If you'd like to report a bug or have any suggestions for improvements then please do get in touch with us using this form. We will get back to you as soon as we can.