CVE-2021-1585 is a critical vulnerability in the Cisco Adaptive Security Device Manager (ASDM) Launcher that allows unauthenticated, remote attackers to execute arbitrary code on a user's operating system. This is due to insufficient signature verification during code exchange between the ASDM and Launcher. An attacker could exploit this via a man-in-the-middle attack, potentially combined with social engineering, to inject and execute code with the Launcher's privileges. Rated 8.1 HIGH on CVSS, this vulnerability has a high attack complexity (AC:H) but allows for complete compromise of confidentiality, integrity, and availability (C:H/I:H/A:H) without user interaction (UI:N) once the initial communication is established. Its EPSS score is exceptionally high, indicating a significant likelihood of exploitation. While not listed in CISA's KEV catalog, the vulnerability has garnered substantial community attention with 2 mentions and 2 media articles, including reports of it being a zero-day. Despite this, no public exploit code is currently available on Metasploit, Nuclei, or ExploitDB.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 7.18.1.152CPE matchmatch criteria | cpe:2.3:a:cisco:adaptive_security_device_manager:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.