CVE-2021-1435

Vulnerability updated 5 months ago (2024-05-04T18:56:56.929Z)
Download STIX
Preview STIX
CVE-2021-1435 is a software vulnerability that was exploited in an attack sequence as revealed by Cisco on October 16, 2023. This flaw, which had been patched earlier, is a remote code execution (RCE) vulnerability present in the web UI of Cisco IOS XE software. In a series of attacks, threat actors initially exploited a newer vulnerability, CVE-2023-20198, to create highest-privilege accounts on internet-facing network devices. Following this, they leveraged CVE-2021-1435 to install a Lua-language implant or backdoor on the compromised systems. The threat actors demonstrated a patch bypass technique, using CVE-2021-1435 to gain administrator level privileges on IOS XE devices, even after it had been patched. The Lua-language implant installed by the attackers potentially allows for continued unauthorized access and control over the affected systems. The exploitation of these vulnerabilities posed a significant threat to the security of the impacted devices and the networks they are part of. However, according to a statement from Cisco Talos, the association of CVE-2021-1435 with these malicious activities has been reassessed. While the initial analysis linked this vulnerability to the exploitation sequence, further investigation led Cisco to determine that CVE-2021-1435 was not associated with this activity. As such, the situation underscores the importance of continuous monitoring and re-evaluation in cybersecurity threat assessment.
Description last updated: 2024-05-04T16:51:31.701Z
What's your take? (Question 1 of 3)
Help tune the shared Cybergeist dataset, assist your peers, and earn karma. Expand the panel to get started.
Aliases We are not currently tracking any aliases
Miscellaneous Associations
Other elements of context that could aid in the identification of relevance
Cisco
Vulnerability
Ios
Implant
Analyst Notes & Discussion
Be the first to leave your mark here! Log in to share your views and vote.
Source Document References
Information about the CVE-2021-1435 Vulnerability was read from the documents corpus below. This display is limited to 20 results, create a free account to see more
PreviewSource LinkCreatedAtTitle
CERT-EU
a year ago
CERT-EU
a year ago
CERT-EU
a year ago
CERT-EU
a year ago
CERT-EU
a year ago
CISA
a year ago
CERT-EU
a year ago
CERT-EU
a year ago
Securityaffairs
a year ago
CERT-EU
a year ago
CISA
a year ago
CERT-EU
a year ago
CERT-EU
a year ago
CERT-EU
a year ago
CERT-EU
a year ago
CERT-EU
a year ago
BankInfoSecurity
a year ago
CERT-EU
a year ago
CERT-EU
a year ago
DARKReading
a year ago