CVE-2021-1618 describes multiple vulnerabilities in the web-based management interface of Cisco Intersight Virtual Appliance. These flaws, stemming from insufficient input validation, allow an authenticated, remote attacker to perform path traversal or command injection. A successful exploit could lead to arbitrary file read/write or root-level command execution on the affected system. The vulnerability carries a CVSS score of 7.2 (High), indicating a significant risk. It requires high privileges (PR:H) but has low attack complexity (AC:L) and no user interaction (UI:N). The potential impact is high across confidentiality, integrity, and availability (C:H/I:H/A:H). Currently, there is no evidence of active exploitation (KEV: No), nor are there public exploit modules available for Metasploit, Nuclei, or ExploitDB. Community discussion and media coverage for this CVE are minimal, which is typical for the vast majority of vulnerabilities.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.0.9-292CPE matchmatch criteria | cpe:2.3:a:cisco:intersight_virtual_appliance:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.3 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.