cbcvebase.
CVE-2021-34727
published 2021-09-23

CVE-2021-34727: A vulnerability in the vDaemon process in Cisco IOS XE SD-WAN Software could allow an unauthenticated, remote attacker to cause a buffer overflow on an…

PriorityP263critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
2.63%
83.8th percentile
A vulnerability in the vDaemon process in Cisco IOS XE SD-WAN Software could allow an unauthenticated, remote attacker to cause a buffer overflow on an affected device. This vulnerability is due to insufficient bounds checking when an affected device processes traffic. An attacker could exploit this vulnerability by sending crafted traffic to the device. A successful exploit could allow the attacker to cause a buffer overflow and possibly execute arbitrary commands with root-level privileges, or cause the device to reload, which could result in a denial of service condition.

Affected

2 ranges
VendorProductVersion rangeFixed in
ciscocisco_ios_xe_sd-wan_software
ciscoios_xe_sd-wan

Detection & IOCsextracted from sources · hover to see the quote

  • Target the vDaemon process on Cisco IOS XE SD-WAN devices; exploitation involves sending crafted traffic that triggers insufficient bounds checking in vDaemon, resulting in a buffer overflow.
  • Monitor for unexpected reloads or crashes of the vDaemon process on Cisco IOS XE SD-WAN devices, which may indicate exploitation attempts (DoS path of the vulnerability).
  • Track Cisco Bug ID CSCvt49022 for patch and detection signature updates related to this vulnerability.
  • ·No workarounds are available for this vulnerability; the only mitigation is applying Cisco's software updates.
  • ·The vulnerability is unauthenticated and remotely exploitable, meaning no credentials or prior access are required for an attacker to attempt exploitation.

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
vendor_cisco9.8CRITICAL
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.