← Back

CVE-2021-1451

nvd nist
Published: Mar 24, 2021Modified: Nov 21, 2024

JSON object

Loading...
9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD

Description

A vulnerability in the Easy Virtual Switching System (VSS) feature of Cisco IOS XE Software for Cisco Catalyst 4500 Series Switches and Cisco Catalyst 4500-X Series Switches could allow an unauthenticated, remote attacker to execute arbitrary code on the underlying Linux operating system of an affected device. The vulnerability is due to incorrect boundary checks of certain values in Easy VSS protocol packets that are destined for an affected device. An attacker could exploit this vulnerability by sending crafted Easy VSS protocol packets to UDP port 5500 while the affected device is in a specific state. When the crafted packet is processed, a buffer overflow condition may occur. A successful exploit could allow the attacker to trigger a denial of service (DoS) condition or execute arbitrary code with root privileges on the underlying Linux operating system of the affected device.

Affected (54)

Products: Cisco: Ios Xe
1 product
Ios Xe
Configuration A
54 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Cisco
Version 15.2(7)e
Version 16.11.2
Version 16.12.5a
Version 17.3.1
Version 3.10.0ce
Version 3.10.0e
Version 3.10.1ae
Version 3.10.1e
Version 3.10.1se
Version 3.10.2e
Version 3.10.3e
Version 3.11.0e
Version 3.11.1ae
Version 3.11.1e
Version 3.11.2ae
Version 3.11.2e
Version 3.11.3ae
Version 3.11.3e
Version 3.6.0be
Version 3.6.0e
Version 3.6.10e
Version 3.6.1e
Version 3.6.2e
Version 3.6.3e
Version 3.6.4e
Version 3.6.5ae
Version 3.6.5be
Version 3.6.5e
Version 3.6.6e
Version 3.6.7e
Version 3.6.8e
Version 3.6.9e
Version 3.7.0e
Version 3.7.1e
Version 3.7.2e
Version 3.7.3e
Version 3.7.4e
Version 3.7.5e
Version 3.8.0e
Version 3.8.10e
Version 3.8.1e
Version 3.8.2e
Version 3.8.3e
Version 3.8.4e
Version 3.8.5ae
Version 3.8.5e
Version 3.8.6e
Version 3.8.7e
Version 3.8.8e
Version 3.8.9e
Version 3.9.0e
Version 3.9.1e
Version 3.9.2be
Version 3.9.2e
Running on/withPlatform Versions
Linux
Linux Kernel
All versions

Timeline

No history available yet.