CVE-2021-34727
published 2021-09-23CVE-2021-34727: A vulnerability in the vDaemon process in Cisco IOS XE SD-WAN Software could allow an unauthenticated, remote attacker to cause a buffer overflow on an…
PriorityP263critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
2.63%
83.8th percentile
A vulnerability in the vDaemon process in Cisco IOS XE SD-WAN Software could allow an unauthenticated, remote attacker to cause a buffer overflow on an affected device. This vulnerability is due to insufficient bounds checking when an affected device processes traffic. An attacker could exploit this vulnerability by sending crafted traffic to the device. A successful exploit could allow the attacker to cause a buffer overflow and possibly execute arbitrary commands with root-level privileges, or cause the device to reload, which could result in a denial of service condition.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | cisco_ios_xe_sd-wan_software | — | — |
| cisco | ios_xe_sd-wan | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Target the vDaemon process on Cisco IOS XE SD-WAN devices; exploitation involves sending crafted traffic that triggers insufficient bounds checking in vDaemon, resulting in a buffer overflow. ↗
- →Monitor for unexpected reloads or crashes of the vDaemon process on Cisco IOS XE SD-WAN devices, which may indicate exploitation attempts (DoS path of the vulnerability). ↗
- →Track Cisco Bug ID CSCvt49022 for patch and detection signature updates related to this vulnerability. ↗
- ·No workarounds are available for this vulnerability; the only mitigation is applying Cisco's software updates. ↗
- ·The vulnerability is unauthenticated and remotely exploitable, meaning no credentials or prior access are required for an attacker to attempt exploitation. ↗
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
vendor_cisco9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco IOS XE SD-WAN Software Buffer Overflow Vulnerability
vendor_cisco·2021-09-22·CVSS 9.8
CVE-2021-34727 [CRITICAL] CWE-120 Cisco IOS XE SD-WAN Software Buffer Overflow Vulnerability
Cisco IOS XE SD-WAN Software Buffer Overflow Vulnerability
A vulnerability in the vDaemon process in Cisco IOS XE SD-WAN Software could allow an unauthenticated, remote attacker to cause a buffer overflow on an affected device.
This vulnerability is due to insufficient bounds checking when an affected device processes traffic. An attacker could exploit this vulnerability by sending crafted traffic to the device. A successful exploit could allow the attacker to cause a buffer overflow and possibly execute arbitrary commands with root-level privileges, or cause the device to reload, which could result in a denial of service condition.
Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.
This advisory is available at
Cisco
Cisco IOS XE SD-WAN Software Buffer Overflow Vulnerability
vendor_cisco·CVSS 3.1
CVE-2021-34727 Cisco IOS XE SD-WAN Software Buffer Overflow Vulnerability
CVE-2021-34727: Cisco IOS XE SD-WAN Software Buffer Overflow Vulnerability
A vulnerability in the vDaemon process in Cisco IOS XE SD-WAN Software could allow an unauthenticated, remote attacker to cause a buffer overflow on an affected device. This vulnerability is due to insufficient bounds checking when an affected device processes traffic. An attacker could exploit this vulnerability by sending crafted traffic to the device. A successful exploit could allow the attacker to cause a buffer overflow and possibly execute arbitrary commands with root- level privileges, or cause the device to reload, which could result in a denial of service condition. Cisco has released software updates that address this vulnerability. There are no
CVSS: 3.1
CWE: CWE-120, CWE-120
Bug IDs: CSCvt49022
GHSA
GHSA-rxw2-fh82-mfcc: A vulnerability in the vDaemon process in Cisco IOS XE SD-WAN Software could allow an unauthenticated, remote attacker to cause a buffer overflow on a
ghsa_unreviewed·2022-05-24
CVE-2021-34727 [CRITICAL] CWE-120 GHSA-rxw2-fh82-mfcc: A vulnerability in the vDaemon process in Cisco IOS XE SD-WAN Software could allow an unauthenticated, remote attacker to cause a buffer overflow on a
A vulnerability in the vDaemon process in Cisco IOS XE SD-WAN Software could allow an unauthenticated, remote attacker to cause a buffer overflow on an affected device. This vulnerability is due to insufficient bounds checking when an affected device processes traffic. An attacker could exploit this vulnerability by sending crafted traffic to the device. A successful exploit could allow the attacker to cause a buffer overflow and possibly execute arbitrary commands with root-level privileges, or cause the device to reload, which could result in a denial of service condition.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2021-09-23
Published