CVE-2021-34713
published 2021-09-09CVE-2021-34713: A vulnerability in the Layer 2 punt code of Cisco IOS XR Software running on Cisco ASR 9000 Series Aggregation Services Routers could allow an unauthenticated…
PriorityP336high7.4CVSS 3.1
AVAACLPRNUINSCCNINAH
EPSS
0.36%
28.3th percentile
A vulnerability in the Layer 2 punt code of Cisco IOS XR Software running on Cisco ASR 9000 Series Aggregation Services Routers could allow an unauthenticated, adjacent attacker to cause the affected line card to reboot. This vulnerability is due to incorrect handling of specific Ethernet frames that cause a spin loop that can make the network processors unresponsive. An attacker could exploit this vulnerability by sending specific types of Ethernet frames on the segment where the affected line cards are attached. A successful exploit could allow the attacker to cause the affected line card to reboot.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | cisco_ios_xr_software | — | — |
| cisco | ios_xr | — | — |
| cisco | ios_xr | >= 6.4 < 6.6.3 | 6.6.3 |
| cisco | ios_xr | >= 6.7 < 6.7.1 | 6.7.1 |
| cisco | ios_xr | >= 7.0 < 7.0.2 | 7.0.2 |
| cisco | ios_xr | >= 7.1 < 7.1.1 | 7.1.1 |
CVSS provenance
nvdv3.17.4HIGHCVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
nvdv2.06.1MEDIUMAV:A/AC:L/Au:N/C:N/I:N/A:C
vendor_cisco7.4HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-ggcm-cr9q-hv99: A vulnerability in the Layer 2 punt code of Cisco IOS XR Software running on Cisco ASR 9000 Series Aggregation Services Routers could allow an unauthe
ghsa_unreviewed·2022-05-24
CVE-2021-34713 [HIGH] GHSA-ggcm-cr9q-hv99: A vulnerability in the Layer 2 punt code of Cisco IOS XR Software running on Cisco ASR 9000 Series Aggregation Services Routers could allow an unauthe
A vulnerability in the Layer 2 punt code of Cisco IOS XR Software running on Cisco ASR 9000 Series Aggregation Services Routers could allow an unauthenticated, adjacent attacker to cause the affected line card to reboot. This vulnerability is due to incorrect handling of specific Ethernet frames that cause a spin loop that can make the network processors unresponsive. An attacker could exploit this vulnerability by sending specific types of Ethernet frames on the segment where the affected line cards are attached. A successful exploit could allow the attacker to cause the affected line card to reboot.
Cisco
Cisco IOS XR Software for ASR 9000 Series Routers Denial of Service Vulnerability
vendor_cisco·2021-09-08·CVSS 7.4
CVE-2021-34713 [HIGH] CWE-399 Cisco IOS XR Software for ASR 9000 Series Routers Denial of Service Vulnerability
Cisco IOS XR Software for ASR 9000 Series Routers Denial of Service Vulnerability
A vulnerability in the Layer 2 punt code of Cisco IOS XR Software running on Cisco ASR 9000 Series Aggregation Services Routers could allow an unauthenticated, adjacent attacker to cause the affected line card to reboot.
This vulnerability is due to incorrect handling of specific Ethernet frames that cause a spin loop that can make the network processors unresponsive. An attacker could exploit this vulnerability by sending specific types of Ethernet frames on the segment where the affected line cards are attached. A successful exploit could allow the attacker to cause the affected line card to reboot.
Cisco has released software updates that address this vulnerability. There are no workarounds that address
Cisco
Cisco IOS XR Software for ASR 9000 Series Routers Denial of Service Vulnerability
vendor_cisco·CVSS 3.1
CVE-2021-34713 Cisco IOS XR Software for ASR 9000 Series Routers Denial of Service Vulnerability
CVE-2021-34713: Cisco IOS XR Software for ASR 9000 Series Routers Denial of Service Vulnerability
A vulnerability in the Layer 2 punt code of Cisco IOS XR Software running on Cisco ASR 9000 Series Aggregation Services Routers could allow an unauthenticated, adjacent attacker to cause the affected line card to reboot. This vulnerability is due to incorrect handling of specific Ethernet frames that cause a spin loop that can make the network processors unresponsive. An attacker could exploit this vulnerability by sending specific types of Ethernet frames on the segment where the affected line cards are attached. A successful exploit could allow the attacker to cause the affected line card to reboot. Cisco has released software updates that address this vulnerability. There are no
CVSS: 3.1
C
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2021-09-09
Published