Rewterz Threat Alert – APT-C-23 aka AridViper Active IOCs
March 25, 2021Rewterz Threat Advisory – CVE-2020-1946 – Apache SpamAssassin command execution
March 25, 2021Rewterz Threat Alert – APT-C-23 aka AridViper Active IOCs
March 25, 2021Rewterz Threat Advisory – CVE-2020-1946 – Apache SpamAssassin command execution
March 25, 2021Severity
Medium
Analysis Summary
CVE-2021-1423
Cisco Aironet Access Points could allow a local authenticated attacker to bypass security restrictions, caused by improper input validation for a specific command. By sending a command with specially-crafted arguments, an attacker could exploit this vulnerability to to overwrite or create files on the device.
Impact
Security bypass
Affected Vendors
Cisco
Affected Products
- Cisco Aironet 1540 Series APs
- Cisco Aironet 1560 Series APs
Remediation
Refer to Cisco advisory for the complete list of affected products and their respective patches.
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ap-foverwrt-HyVXvrtb