CVE-2021-1593 is a DLL injection vulnerability in Cisco Packet Tracer for Windows, stemming from incorrect handling of directory paths. An authenticated, local attacker with valid system credentials could exploit this by inserting a malicious configuration file, leading to arbitrary code execution with elevated privileges. Rated High (CVSS 7.3), the attack requires local access and user interaction (UI:R), but can result in high impact to confidentiality, integrity, and availability. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion, despite some media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
7.2.0CPE matchmatch criteria | cpe:2.3:a:cisco:packet_tracer:7.2.0:*:*:*:*:*:*:* | ||
7.2.1CPE matchmatch criteria | cpe:2.3:a:cisco:packet_tracer:7.2.1:*:*:*:*:*:*:* | ||
7.2.2CPE matchmatch criteria | cpe:2.3:a:cisco:packet_tracer:7.2.2:*:*:*:*:*:*:* | ||
7.3.0CPE matchmatch criteria | cpe:2.3:a:cisco:packet_tracer:7.3.0:*:*:*:*:*:*:* | ||
7.3.1CPE matchmatch criteria | cpe:2.3:a:cisco:packet_tracer:7.3.1:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.