CVE-2021-34714
published 2021-09-23CVE-2021-34714: A vulnerability in the Unidirectional Link Detection (UDLD) feature of Cisco FXOS Software, Cisco IOS Software, Cisco IOS XE Software, Cisco IOS XR Software…
PriorityP337high7.4CVSS 3.1
AVAACLPRNUINSCCNINAH
EPSS
0.40%
32.8th percentile
A vulnerability in the Unidirectional Link Detection (UDLD) feature of Cisco FXOS Software, Cisco IOS Software, Cisco IOS XE Software, Cisco IOS XR Software, and Cisco NX-OS Software could allow an unauthenticated, adjacent attacker to cause an affected device to reload. This vulnerability is due to improper input validation of the UDLD packets. An attacker could exploit this vulnerability by sending specifically crafted UDLD packets to an affected device. A successful exploit could allow the attacker to cause the affected device to reload, resulting in a denial of service (DoS) condition. Note: The UDLD feature is disabled by default, and the conditions to exploit this vulnerability are strict. An attacker must have full control of a directly connected device. On Cisco IOS XR devices, the impact is limited to the reload of the UDLD process.
Affected
33 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | cisco_ios | — | — |
| cisco | firepower_extensible_operating_system | <= 8.4\(3.115\) | — |
| cisco | firepower_extensible_operating_system | <= 7.0\(3\)i7\(9\) | — |
| cisco | firepower_extensible_operating_system | <= 7.3\(8\)n1\(1\) | — |
| cisco | firepower_extensible_operating_system | <= 3.2\(3o\)a | — |
| cisco | firepower_extensible_operating_system | <= 4.1\(1a\)a | — |
| cisco | fxos | >= 2.2 < 2.2.2.148 | 2.2.2.148 |
| cisco | fxos | >= 2.3 < 2.3.1.216 | 2.3.1.216 |
| cisco | fxos | >= 2.4 < 2.4.1.273 | 2.4.1.273 |
| cisco | fxos | >= 2.6 < 2.6.1.224 | 2.6.1.224 |
| cisco | fxos | >= 2.7 < 2.7.1.143 | 2.7.1.143 |
| cisco | fxos | >= 2.8 < 2.8.1.143 | 2.8.1.143 |
| cisco | fxos | >= 2.9 < 2.9.1.135 | 2.9.1.135 |
| cisco | ios | <= 8.4\(3.115\) | — |
| cisco | ios | <= 7.0\(3\)i7\(9\) | — |
| cisco | ios | <= 7.3\(8\)n1\(1\) | — |
| cisco | ios | <= 3.2\(3o\)a | — |
| cisco | ios | <= 4.1\(1a\)a | — |
| cisco | ios_xe | <= 8.4\(3.115\) | — |
| cisco | ios_xe | <= 7.0\(3\)i7\(9\) | — |
| cisco | ios_xe | <= 7.3\(8\)n1\(1\) | — |
| cisco | ios_xe | <= 3.2\(3o\)a | — |
| cisco | ios_xe | <= 4.1\(1a\)a | — |
| cisco | ios_xr | <= 8.4\(3.115\) | — |
| cisco | ios_xr | <= 7.0\(3\)i7\(9\) | — |
CVSS provenance
nvdv3.17.4HIGHCVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
nvdv2.05.7MEDIUMAV:A/AC:M/Au:N/C:N/I:N/A:C
vendor_cisco7.4HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Multiple Cisco Operating Systems Unidirectional Link Detection Denial of Service Vulnerability
vendor_cisco·2021-09-22·CVSS 7.4
CVE-2021-34714 [HIGH] CWE-20 Multiple Cisco Operating Systems Unidirectional Link Detection Denial of Service Vulnerability
Multiple Cisco Operating Systems Unidirectional Link Detection Denial of Service Vulnerability
A vulnerability in the Unidirectional Link Detection (UDLD) feature of Cisco FXOS Software, Cisco IOS Software, Cisco IOS XE Software, Cisco IOS XR Software, and Cisco NX-OS Software could allow an unauthenticated, adjacent attacker to cause an affected device to reload.
This vulnerability is due to improper input validation of the UDLD packets. An attacker could exploit this vulnerability by sending specifically crafted UDLD packets to an affected device. A successful exploit could allow the attacker to cause the affected device to reload, resulting in a denial of service (DoS) condition.
Note: The UDLD feature is disabled by default, and the conditions to exploit this vulnerability are strict
Cisco
Multiple Cisco Operating Systems Unidirectional Link Detection Denial of Service Vulnerability
vendor_cisco·CVSS 3.1
CVE-2021-34714 Multiple Cisco Operating Systems Unidirectional Link Detection Denial of Service Vulnerability
CVE-2021-34714: Multiple Cisco Operating Systems Unidirectional Link Detection Denial of Service Vulnerability
A vulnerability in the Unidirectional Link Detection (UDLD) feature of Cisco FXOS Software, Cisco IOS Software, Cisco IOS XE Software, Cisco IOS XR Software, and Cisco NX-OS Software could allow an unauthenticated, adjacent attacker to cause an affected device to reload. This vulnerability is due to improper input validation of the UDLD packets. An attacker could exploit this vulnerability by sending specifically crafted UDLD packets to an affected device. A successful exploit could allow the attacker to cause the affected device to reload, resulting in a denial of service (DoS) condition. Note: The UDLD feature is disabled by default, and the conditions to exploit this vulnerabil
GHSA
GHSA-wjvw-6gq9-r937: A vulnerability in the Unidirectional Link Detection (UDLD) feature of Cisco FXOS Software, Cisco IOS Software, Cisco IOS XE Software, Cisco IOS XR So
ghsa_unreviewed·2022-05-24
CVE-2021-34714 [HIGH] CWE-20 GHSA-wjvw-6gq9-r937: A vulnerability in the Unidirectional Link Detection (UDLD) feature of Cisco FXOS Software, Cisco IOS Software, Cisco IOS XE Software, Cisco IOS XR So
A vulnerability in the Unidirectional Link Detection (UDLD) feature of Cisco FXOS Software, Cisco IOS Software, Cisco IOS XE Software, Cisco IOS XR Software, and Cisco NX-OS Software could allow an unauthenticated, adjacent attacker to cause an affected device to reload. This vulnerability is due to improper input validation of the UDLD packets. An attacker could exploit this vulnerability by sending specifically crafted UDLD packets to an affected device. A successful exploit could allow the attacker to cause the affected device to reload, resulting in a denial of service (DoS) condition. Note: The UDLD feature is disabled by default, and the conditions to exploit this vulnerability are strict. An attacker must have full control of a directly connected device. On Cisco IOS XR devices, the
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2021-09-23
Published