CVE-2021-34748 is a high-severity command injection vulnerability affecting the web-based management interface of Cisco Intersight Virtual Appliance. An authenticated, remote attacker can exploit insufficient input validation to execute arbitrary commands with root privileges. This vulnerability has a CVSS score of 8.8 (High), indicating a low attack complexity and significant impact on confidentiality, integrity, and availability. While there is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB) is not available, and it has received limited community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 1.0.9-150, <= 1.0.9-292CPE matchmatch criteria | cpe:2.3:a:cisco:intersight_virtual_appliance:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.