Rewterz Threat Advisory – CVE-2021-30641 – Apache HTTP Server Remote Code Execution
June 16, 2021Rewterz Threat Advisory – Cisco Email Security Appliance and Cisco Web Security Appliance Certificate Validation Vulnerability
June 17, 2021Rewterz Threat Advisory – CVE-2021-30641 – Apache HTTP Server Remote Code Execution
June 16, 2021Rewterz Threat Advisory – Cisco Email Security Appliance and Cisco Web Security Appliance Certificate Validation Vulnerability
June 17, 2021Severity
Medium
Analysis Summary
CVE-2021-1541
Cisco Small Business 220 Series Smart Switches could allow a remote authenticated attacker to execute arbitrary commands on the system, caused by improper parameter validation for TFTP configuration parameters. By using specially-crafted input for specific TFTP configuration parameters, an attacker could exploit this vulnerability to execute arbitrary commands as a root user on the underlying operating system.
CVE-2021-1542
Cisco Small Business 220 Series Smart Switches could allow a remote attacker to gain elevated privileges on the system, caused by the use of weak session management for session identifier values. By using reconnaissance methods to determine how to craft a valid session identifier, an attacker could exploit this vulnerability to take actions within the management interface with administrative privileges.
CVE-2021-1543
Cisco Small Business 220 Series Smart Switches are vulnerable to cross-site scripting, caused by improper validation of user-supplied input by the web-based management interface. A remote attacker could exploit this vulnerability using a specially-crafted URL to execute script in a victim’s Web browser within the security context of the hosting Web site, once the URL is clicked. An attacker could use this vulnerability to steal the victim’s cookie-based authentication credentials.
CVE-2021-1571
Cisco Small Business 220 Series Smart Switches are vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim’s Web browser within the security context of the hosting site.
Impact
- Remote Code Execution
- Privilege Escalation
- Cross-Site Scripting
Affected Vendors
Cisco
Affected Products
- Cisco Small Business 220 Series Smart Switches
Remediation
Upgrade to the Cisco Small Business 220 Series Smart Switches firmware releases 1.2.0.6 and later from https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ciscosb-multivulns-Wwyb7s5E