CVE-2021-1540 describes multiple authorization bypass vulnerabilities in Cisco ASR 5000 Series Software (StarOS), impacting products like ASR 5000, ASR 5500, ASR 5700, StarOS, and Virtualized Packet Core. With a CVSS score of 7.2 (High), an authenticated, remote attacker could exploit this to execute a subset of CLI commands, leading to high impact on confidentiality, integrity, and availability. While the EPSS score is low and there's no evidence of active exploitation, public exploit code, or significant community discussion, the vulnerability remains a concern for affected systems.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 21.16.9CPE matchmatch criteria | cpe:2.3:o:cisco:staros:*:*:*:*:*:*:*:* | ||
>= 21.17.0, < 21.17.10CPE matchmatch criteria | cpe:2.3:o:cisco:staros:*:*:*:*:*:*:*:* | ||
>= 21.18.0, < 21.18.16CPE matchmatch criteria | cpe:2.3:o:cisco:staros:*:*:*:*:*:*:*:* | ||
>= 21.19.0, < 21.19.11CPE matchmatch criteria | cpe:2.3:o:cisco:staros:*:*:*:*:*:*:*:* | ||
>= 21.19.n, < 21.19.n7CPE matchmatch criteria | cpe:2.3:o:cisco:staros:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.3 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.