CVE-2021-27853
published 2022-09-27CVE-2021-27853: Layer 2 network filtering capabilities such as IPv6 RA guard or ARP inspection can be bypassed using combinations of VLAN 0 headers and LLC/SNAP headers.
PriorityP420medium4.7CVSS 3.1
AVAACLPRNUINSCCNILAN
EPSS
0.71%
49.2th percentile
Layer 2 network filtering capabilities such as IPv6 RA guard or ARP inspection can be bypassed using combinations of VLAN 0 headers and LLC/SNAP headers.
Affected
94 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | catalyst_6503-e_firmware | — | — |
| cisco | catalyst_6504-e_firmware | — | — |
| cisco | catalyst_6506-e_firmware | — | — |
| cisco | catalyst_6509-e_firmware | — | — |
| cisco | catalyst_6509-neb-a_firmware | — | — |
| cisco | catalyst_6509-v-e_firmware | — | — |
| cisco | catalyst_6513-e_firmware | — | — |
| cisco | catalyst_6800ia_firmware | — | — |
| cisco | catalyst_6807-xl_firmware | — | — |
| cisco | catalyst_6840-x_firmware | — | — |
| cisco | catalyst_6880-x_firmware | — | — |
| cisco | catalyst_c6816-x-le_firmware | — | — |
| cisco | catalyst_c6824-x-le-40g_firmware | — | — |
| cisco | catalyst_c6832-x-le_firmware | — | — |
| cisco | catalyst_c6840-x-le-40g_firmware | — | — |
| cisco | ios_xe | — | — |
| cisco | ios_xe | — | — |
| cisco | ios_xe | — | — |
| cisco | ios_xe | — | — |
| cisco | ios_xe | — | — |
| cisco | n9k-c9316d-gx_firmware | — | — |
| cisco | n9k-c9332d-gx2b_firmware | — | — |
| cisco | n9k-c9348d-gx2a_firmware | — | — |
| cisco | n9k-c93600cd-gx_firmware | — | — |
| cisco | n9k-c9364d-gx2a_firmware | — | — |
CVSS provenance
nvdv3.14.7MEDIUMCVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N
vendor_cisco4.7MEDIUM
vendor_redhat4.7MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Palo Alto
PAN-SA-2025-0006 Informational Bulletin: Impact of OSS CVEs in PAN-OS
vendor_paloalto·2025-02-12·CVSS 7.1
CVE-2015-5312 [HIGH] PAN-SA-2025-0006 Informational Bulletin: Impact of OSS CVEs in PAN-OS
PAN-SA-2025-0006 Informational Bulletin: Impact of OSS CVEs in PAN-OS
T he Palo Alto Networks Product Security Assurance team has evaluated the following open source software (OSS) CVEs as they relate to PAN-OS software. While PAN-OS software may include the
CVEs: CVE-2015-5312, CVE-2016-4607, CVE-2016-4608, CVE-2016-4609, CVE-2016-4738, CVE-2018-1111, CVE-2018-14634, CVE-2018-18653, CVE-2019-0145, CVE-2019-8331, CVE-2020-0599, CVE-2020-14343, CVE-2020-14779, CVE-2020-27844, CVE-2020-29569, CVE-2021-21315, CVE-2021-27853, CVE-2021-27854, CVE-2021-27861, CVE-2021-27862, CVE-2021-3618, CVE-2021-3711, CVE-2022-2097, CVE-2022-22816, CVE-2022-40303, CVE-2022-41723, CVE-2022-41741, CVE-2022-41742, CVE-2023-3247, CVE-2023-38408, CVE-2023-44466, CVE-2023-50781, CVE-2023-50782, CVE-2024-12084, CV
Cisco
Vulnerabilities in Layer 2 Network Security Controls Affecting Cisco Products: September 2022
vendor_cisco·2022-09-27·CVSS 4.7
CVE-2021-27853 [MEDIUM] CWE-284 Vulnerabilities in Layer 2 Network Security Controls Affecting Cisco Products: September 2022
Vulnerabilities in Layer 2 Network Security Controls Affecting Cisco Products: September 2022
On September 27, 2022, the following vulnerabilities affecting Cisco products were disclosed by Cert/CC as part of VU855201, titled L2 network security controls can be bypassed using VLAN 0 stacking and/or 802.3 headers:
CVE-2021-27853: Layer 2 network filtering capabilities such as IPv6 RA guard or ARP inspection can be bypassed using a combination of VLAN 0 headers and LLC/SNAP headers.
CVE-2021-27854: Layer 2 network filtering capabilities such as IPv6 RA guard can be bypassed using a combination of VLAN 0 headers, LLC/SNAP headers in Ethernet to Wifi frame translation, and in the reverse—Wifi to Ethernet.
CVE-2021-27861: Layer 2 network filtering capabilities such as IPv6 RA guard can be byp
Red Hat
kernel: layer 2 network filtering capabilities bypass
vendor_redhat·2021-09-27·CVSS 4.7
CVE-2021-27853 [MEDIUM] kernel: layer 2 network filtering capabilities bypass
kernel: layer 2 network filtering capabilities bypass
Layer 2 network filtering capabilities such as IPv6 RA guard or ARP inspection can be bypassed using combinations of VLAN 0 headers and LLC/SNAP headers.
Layer 2 network filtering capabilities such as IPv6 RA guard or ARP inspection can be bypassed using combinations of VLAN 0 headers and LLC/SNAP headers.
Statement: Red Hat deems this to be a configuration issue. There is no vulnerability in the Linux kernel itself, there is a lot of ways to misuse the filtering facilities provided by the kernel and do insecure filtering rules, but you also have everything to actually set up secure rules.
Package: kernel (Red Hat Enterprise Linux 6) - Not affected
Package: kernel (Red Hat Enterprise Linux 7) - Not affected
Package: kernel-rt (Red
Cisco
Vulnerabilities in Layer 2 Network Security Controls Affecting Cisco Products: September 2022
vendor_cisco·CVSS 3.1
CVE-2021-27853 Vulnerabilities in Layer 2 Network Security Controls Affecting Cisco Products: September 2022
CVE-2021-27853: Vulnerabilities in Layer 2 Network Security Controls Affecting Cisco Products: September 2022
On September 27, 2022, the following vulnerabilities affecting Cisco products were disclosed by Cert/CC as part of VU855201, titled L2 network security controls can be bypassed using VLAN 0 stacking and/or 802.3 headers : CVE-2021-27853: Layer 2 network filtering capabilities such as IPv6 RA guard or ARP inspection can be bypassed using a combination of VLAN 0 headers and LLC/SNAP headers. CVE-2021-27854: Layer 2 network filtering capabilities such as IPv6 RA guard can be bypassed using a combination of VLAN 0 headers, LLC/SNAP headers in Ethernet to Wifi frame translation, and in the reverse-Wifi to Ethernet. CVE-2021-27861: Layer 2 network filtering capabilities such as IPv6 RA g
Cisco
Vulnerabilities in Layer 2 Network Security Controls Affecting Cisco Products: September 2022
vendor_cisco·CVSS 3.1
CVE-2021-27861 Vulnerabilities in Layer 2 Network Security Controls Affecting Cisco Products: September 2022
CVE-2021-27861: Vulnerabilities in Layer 2 Network Security Controls Affecting Cisco Products: September 2022
On September 27, 2022, the following vulnerabilities affecting Cisco products were disclosed by Cert/CC as part of VU855201, titled L2 network security controls can be bypassed using VLAN 0 stacking and/or 802.3 headers : CVE-2021-27853: Layer 2 network filtering capabilities such as IPv6 RA guard or ARP inspection can be bypassed using a combination of VLAN 0 headers and LLC/SNAP headers. CVE-2021-27854: Layer 2 network filtering capabilities such as IPv6 RA guard can be bypassed using a combination of VLAN 0 headers, LLC/SNAP headers in Ethernet to Wifi frame translation, and in the reverse-Wifi to Ethernet. CVE-2021-27861: Layer 2 network filtering capabilities such as IPv6 RA g
Cisco
Vulnerabilities in Layer 2 Network Security Controls Affecting Cisco Products: September 2022
vendor_cisco·CVSS 3.1
CVE-2021-27862 Vulnerabilities in Layer 2 Network Security Controls Affecting Cisco Products: September 2022
CVE-2021-27862: Vulnerabilities in Layer 2 Network Security Controls Affecting Cisco Products: September 2022
On September 27, 2022, the following vulnerabilities affecting Cisco products were disclosed by Cert/CC as part of VU855201, titled L2 network security controls can be bypassed using VLAN 0 stacking and/or 802.3 headers : CVE-2021-27853: Layer 2 network filtering capabilities such as IPv6 RA guard or ARP inspection can be bypassed using a combination of VLAN 0 headers and LLC/SNAP headers. CVE-2021-27854: Layer 2 network filtering capabilities such as IPv6 RA guard can be bypassed using a combination of VLAN 0 headers, LLC/SNAP headers in Ethernet to Wifi frame translation, and in the reverse-Wifi to Ethernet. CVE-2021-27861: Layer 2 network filtering capabilities such as IPv6 RA g
Cisco
Vulnerabilities in Layer 2 Network Security Controls Affecting Cisco Products: September 2022
vendor_cisco·CVSS 3.1
CVE-2021-27854 Vulnerabilities in Layer 2 Network Security Controls Affecting Cisco Products: September 2022
CVE-2021-27854: Vulnerabilities in Layer 2 Network Security Controls Affecting Cisco Products: September 2022
On September 27, 2022, the following vulnerabilities affecting Cisco products were disclosed by Cert/CC as part of VU855201, titled L2 network security controls can be bypassed using VLAN 0 stacking and/or 802.3 headers : CVE-2021-27853: Layer 2 network filtering capabilities such as IPv6 RA guard or ARP inspection can be bypassed using a combination of VLAN 0 headers and LLC/SNAP headers. CVE-2021-27854: Layer 2 network filtering capabilities such as IPv6 RA guard can be bypassed using a combination of VLAN 0 headers, LLC/SNAP headers in Ethernet to Wifi frame translation, and in the reverse-Wifi to Ethernet. CVE-2021-27861: Layer 2 network filtering capabilities such as IPv6 RA g
GHSA
GHSA-v8jg-p3fp-g968: Layer 2 network filtering capabilities such as IPv6 RA guard or ARP inspection can be bypassed using combinations of VLAN 0 headers and LLC/SNAP heade
ghsa_unreviewed·2022-09-28
CVE-2021-27853 [MEDIUM] CWE-290 GHSA-v8jg-p3fp-g968: Layer 2 network filtering capabilities such as IPv6 RA guard or ARP inspection can be bypassed using combinations of VLAN 0 headers and LLC/SNAP heade
Layer 2 network filtering capabilities such as IPv6 RA guard or ARP inspection can be bypassed using combinations of VLAN 0 headers and LLC/SNAP headers.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://blog.champtar.fr/VLAN0_LLC_SNAP/https://datatracker.ietf.org/doc/draft-ietf-v6ops-ra-guard/08/https://kb.cert.org/vuls/id/855201https://standards.ieee.org/ieee/802.1Q/10323/https://standards.ieee.org/ieee/802.2/1048/https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-VU855201-J3z8CKTXhttps://blog.champtar.fr/VLAN0_LLC_SNAP/https://datatracker.ietf.org/doc/draft-ietf-v6ops-ra-guard/08/https://kb.cert.org/vuls/id/855201https://standards.ieee.org/ieee/802.1Q/10323/https://standards.ieee.org/ieee/802.2/1048/https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-VU855201-J3z8CKTXhttps://www.kb.cert.org/vuls/id/855201
2022-09-27
Published