Get real-time updates on Telegram
CVE-2021-1432: ios xe 3.15.1xbs, 3.15.2xbs, 16.12.1 (+22 more affected versions); +2 more affected products
CVE-2021-1432. CVSS 3.1 base score 7.3 (HIGH, NVD). EPSS 0.0034 (percentile 0.25367), scored 2026-10-06.
Affected technology
ios xe · 3.15.1xbs
cisco
ios xe · 3.15.2xbs
cisco
ios xe · 16.12.1
cisco
ios xe · 16.12.1a
cisco
ios xe · 16.12.1c
cisco
ios xe · 16.12.1s
cisco
ios xe · 16.12.1t
cisco
ios xe · 16.12.1w
cisco
ios xe · 16.12.1x
cisco
ios xe · 16.12.1y
cisco
ios xe · 16.12.1z
cisco
ios xe · 16.12.1za
cisco
ios xe · 16.12.2
cisco
ios xe · 16.12.2a
cisco
ios xe · 16.12.2s
cisco
ios xe · 16.12.2t
cisco
ios xe · 16.12.3
cisco
ios xe · 16.12.3a
cisco
ios xe · 16.12.3s
cisco
ios xe · 16.12.4
cisco
ios xe · 16.12.4a
cisco
ios xe · 17.2.1
cisco
ios xe · 17.2.1a
cisco
ios xe · 17.2.1r
cisco
ios xe · 17.2.1v
cisco
ios xe sd-wan · Version not applicable in the source CPE
cisco
Cisco IOS XE Software · n/a
Cisco
Component: Not specified by the source
Attack conditions (Vendor/CNA, CVSS 3.1): Local · Low privileges required · User interaction required
Attack conditions (NVD, CVSS 3.1): Local · Low privileges required · User interaction required
What an attacker can do
An authenticated, local attacker could execute arbitrary commands on the underlying operating system as the root user. Vendor/CNA’s CVSS 3.1 assessment (base score 7.3/10) rates confidentiality, integrity and availability impact as high. NVD’s CVSS 3.1 assessment (base score 7.3/10) rates confidentiality, integrity and availability impact as high.
- CWE
- CWE-20, CWE-74
- CCR priority
- 29.3 /100 (P4)
- CVSS 3.1
- 7.3 /10 · CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H · NVD
- EPSS
- 0.0034 · percentile 0.25367 · 2026-10-06
- KEV
- no
Provenance
- FIRST EPSS daily exploit-probability · Source record · observed 2026-10-07 11:53:15.413517+00:00 UTC
- GitHub Advisory Database · Source record · observed 2026-10-07 13:20:35.851963+00:00 UTC
- NVD CVE API 2.0 · Source record · observed 2026-10-07 11:49:32.540646+00:00 UTC
Stable permalink: https://cybercodered.org/item/cve-cve-2021-1432.html