CVE-2021-1391 is a privilege escalation vulnerability in the dragonite debugger of Cisco IOS XE Software, affecting Cisco IOS and IOS XE products. It allows an authenticated, local attacker with privilege level 15 to escalate to root privileges. The vulnerability stems from residual development testing scripts that bypass the consent token mechanism. With a CVSS score of 6.7 (Medium), exploitation requires high privileges and local access, but can lead to complete compromise of confidentiality, integrity, and availability. There is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
12.2\(6\)i1CPE matchmatch criteria | cpe:2.3:o:cisco:ios:12.2\(6\)i1:*:*:*:*:*:*:* | ||
15.0\(2\)se13aCPE matchmatch criteria | cpe:2.3:o:cisco:ios:15.0\(2\)se13a:*:*:*:*:*:*:* | ||
15.1\(3\)svr1CPE matchmatch criteria | cpe:2.3:o:cisco:ios:15.1\(3\)svr1:*:*:*:*:*:*:* | ||
15.1\(3\)svr2CPE matchmatch criteria | cpe:2.3:o:cisco:ios:15.1\(3\)svr2:*:*:*:*:*:*:* | ||
15.1\(3\)svr3CPE matchmatch criteria | cpe:2.3:o:cisco:ios:15.1\(3\)svr3:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.