CYBER CODE RED

Get real-time updates on Telegram

P4Verified

CVE-2021-1432: ios xe 3.15.1xbs, 3.15.2xbs, 16.12.1 (+22 more affected versions); +2 more affected products

CVE-2021-1432. CVSS 3.1 base score 7.3 (HIGH, NVD). EPSS 0.0034 (percentile 0.25367), scored 2026-10-06.

Affected technology

ios xe · 3.15.1xbs
cisco

ios xe · 3.15.2xbs
cisco

ios xe · 16.12.1
cisco

ios xe · 16.12.1a
cisco

ios xe · 16.12.1c
cisco

ios xe · 16.12.1s
cisco

ios xe · 16.12.1t
cisco

ios xe · 16.12.1w
cisco

ios xe · 16.12.1x
cisco

ios xe · 16.12.1y
cisco

ios xe · 16.12.1z
cisco

ios xe · 16.12.1za
cisco

ios xe · 16.12.2
cisco

ios xe · 16.12.2a
cisco

ios xe · 16.12.2s
cisco

ios xe · 16.12.2t
cisco

ios xe · 16.12.3
cisco

ios xe · 16.12.3a
cisco

ios xe · 16.12.3s
cisco

ios xe · 16.12.4
cisco

ios xe · 16.12.4a
cisco

ios xe · 17.2.1
cisco

ios xe · 17.2.1a
cisco

ios xe · 17.2.1r
cisco

ios xe · 17.2.1v
cisco

ios xe sd-wan · Version not applicable in the source CPE
cisco

Cisco IOS XE Software · n/a
Cisco

Component: Not specified by the source

Attack conditions (Vendor/CNA, CVSS 3.1): Local · Low privileges required · User interaction required

Attack conditions (NVD, CVSS 3.1): Local · Low privileges required · User interaction required

What an attacker can do

An authenticated, local attacker could execute arbitrary commands on the underlying operating system as the root user. Vendor/CNA’s CVSS 3.1 assessment (base score 7.3/10) rates confidentiality, integrity and availability impact as high. NVD’s CVSS 3.1 assessment (base score 7.3/10) rates confidentiality, integrity and availability impact as high.

Published

CWE
CWE-20, CWE-74
CCR priority
29.3 /100 (P4)
CVSS 3.1
7.3 /10 · CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H · NVD
EPSS
0.0034 · percentile 0.25367 · 2026-10-06
KEV
no

Provenance

Stable permalink: https://cybercodered.org/item/cve-cve-2021-1432.html