cbcvebase.
CVE-2021-27853
published 2022-09-27

CVE-2021-27853: Layer 2 network filtering capabilities such as IPv6 RA guard or ARP inspection can be bypassed using combinations of VLAN 0 headers and LLC/SNAP headers.

PriorityP420medium4.7CVSS 3.1
AVAACLPRNUINSCCNILAN
EPSS
0.71%
49.2th percentile
Layer 2 network filtering capabilities such as IPv6 RA guard or ARP inspection can be bypassed using combinations of VLAN 0 headers and LLC/SNAP headers.

Affected

94 ranges· showing 25
VendorProductVersion rangeFixed in
ciscocatalyst_6503-e_firmware
ciscocatalyst_6504-e_firmware
ciscocatalyst_6506-e_firmware
ciscocatalyst_6509-e_firmware
ciscocatalyst_6509-neb-a_firmware
ciscocatalyst_6509-v-e_firmware
ciscocatalyst_6513-e_firmware
ciscocatalyst_6800ia_firmware
ciscocatalyst_6807-xl_firmware
ciscocatalyst_6840-x_firmware
ciscocatalyst_6880-x_firmware
ciscocatalyst_c6816-x-le_firmware
ciscocatalyst_c6824-x-le-40g_firmware
ciscocatalyst_c6832-x-le_firmware
ciscocatalyst_c6840-x-le-40g_firmware
ciscoios_xe
ciscoios_xe
ciscoios_xe
ciscoios_xe
ciscoios_xe
ciscon9k-c9316d-gx_firmware
ciscon9k-c9332d-gx2b_firmware
ciscon9k-c9348d-gx2a_firmware
ciscon9k-c93600cd-gx_firmware
ciscon9k-c9364d-gx2a_firmware

CVSS provenance

nvdv3.14.7MEDIUMCVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N
vendor_cisco4.7MEDIUM
vendor_redhat4.7MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.