Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-6859 | A vulnerability in the CLI command permissions of Cisco IOS and Cisco IOS XE Software could allow an authenticated, local attacker to retrieve the password for Common Industrial Protocol (CIP) and then remotely configure the device as an administrative user. This vulnerability exists because incorrect permissions are associated with the show cip security CLI command. An attacker could exploit this vulnerability by issuing the command to retrieve the password for CIP on an affected device. A successful exploit could allow the attacker to reconfigure the device. |
Sat, 09 Nov 2024 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: cisco
Published:
Updated: 2024-11-08T23:33:05.994Z
Reserved: 2020-11-13T00:00:00.000Z
Link: CVE-2021-1392
Updated: 2024-08-03T16:11:16.883Z
Status : Modified
Published: 2021-03-24T20:15:14.057
Modified: 2026-06-17T03:31:40.123
Link: CVE-2021-1392
No data.
OpenCVE Enrichment
No data.
-
CWE-522
Insufficiently Protected Credentials
EUVD