Back to overview

CVE-2021-34770

CRITICAL
10.0
CVSS 3.1
Description
A vulnerability in the Control and Provisioning of Wireless Access Points (CAPWAP) protocol processing of Cisco IOS XE Software for Cisco Catalyst 9000 Family Wireless Controllers could allow an unauthenticated, remote attacker to execute arbitrary code with administrative privileges or cause a denial of service (DoS) condition on an affected device. The vulnerability is due to a logic error that occurs during the validation of CAPWAP packets. An attacker could exploit this vulnerability by sending a crafted CAPWAP packet to an affected device. A successful exploit could allow the attacker to execute arbitrary code with administrative privileges or cause the affected device to crash and reload, resulting in a DoS condition.

Metadata

CVE ID
CVE-2021-34770
State
PUBLISHED
Assigner
cisco
Reserved
2021-06-15 00:00 UTC
Published
2021-09-23 02:27 UTC
Last updated
2024-11-07 21:57 UTC
Primary CWE
CWE-122
CWE-122
Vendor / Product
Cisco / Cisco IOS XE Software
Sources
cve.org  ·  NVD

Severity & Metrics

10.0 CRITICAL CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
SSVC — CISA Coordinator
Exploitation
none
Automatable
yes
Tech. Impact
total
Affected products (1)
VendorProductPlatformVersions
Cisco Cisco IOS XE Software n/a
Weakness (CWE)
CWESourceDescription
CWE-122 cna CWE-122
CVSS scores (1)
ScoreSeverityVersionSourceVector
10.0 CRITICAL 3.1 cna CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
References (1)
Back to overview