Lucene search

K
cveCiscoCVE-2021-34719
HistorySep 09, 2021 - 5:15 a.m.

CVE-2021-34719

2021-09-0905:15:11
CWE-78
cisco
web.nvd.nist.gov
49
cve-2021-34719
cisco
ios xr
software
cli
vulnerabilities
local attacker
privilege escalation

CVSS2

7.2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:C/I:C/A:C

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

AI Score

7.4

Confidence

High

EPSS

0

Percentile

5.2%

Multiple vulnerabilities in the CLI of Cisco IOS XR Software could allow an authenticated, local attacker with a low-privileged account to elevate privileges on an affected device. For more information about these vulnerabilities, see the Details section of this advisory.

Affected configurations

Nvd
Node
ciscoasr_9000v-v2Match-
OR
ciscoasr_9001Match-
OR
ciscoasr_9006Match-
OR
ciscoasr_9010Match-
OR
ciscoasr_9901Match-
OR
ciscoasr_9902Match-
OR
ciscoasr_9903Match-
OR
ciscoasr_9904Match-
OR
ciscoasr_9906Match-
OR
ciscoasr_9910Match-
OR
ciscoasr_9912Match-
OR
ciscoasr_9922Match-
AND
ciscoios_xrRange<7.3.2
OR
ciscoios_xrRange7.4.07.4.1
Node
ciscoios_xrvMatch-
OR
ciscoios_xrv_9000Match-
AND
ciscoios_xrRange<7.3.2
OR
ciscoios_xrRange7.4.07.4.1
Node
cisconcs_520Match-
OR
cisconcs_540Match-
OR
cisconcs_540_fronthaulMatch-
OR
cisconcs_560-4Match-
OR
cisconcs_560-7Match-
AND
ciscoios_xrRange<7.3.2
OR
ciscoios_xrRange7.4.07.4.1
Node
ciscoios_xrRange<7.3.2
OR
ciscoios_xrRange7.4.07.4.1
AND
cisconcs_5001Match-
OR
cisconcs_5002Match-
OR
cisconcs_5011Match-
Node
ciscoios_xrRange<7.3.2
OR
ciscoios_xrRange7.4.07.4.1
AND
cisconcs_4009Match-
OR
cisconcs_4016Match-
Node
ciscoios_xrRange<7.3.2
OR
ciscoios_xrRange7.4.07.4.1
AND
cisconcs_5501Match-
OR
cisconcs_5501-seMatch-
OR
cisconcs_5502Match-
OR
cisconcs_5502-seMatch-
OR
cisconcs_5508Match-
OR
cisconcs_5516Match-
Node
ciscoios_xrRange<7.3.2
OR
ciscoios_xrRange7.4.07.4.1
AND
cisconcs_6000Match-
OR
cisconcs_6008Match-
Node
ciscoios_xrRange<7.3.2
OR
ciscoios_xrRange7.4.07.4.1
AND
cisconcs_1001Match-
OR
cisconcs_1002Match-
OR
cisconcs_1004Match-
Node
ciscoios_xrRange<7.3.2
OR
ciscoios_xrRange7.4.07.4.1
AND
cisco8101-32fhMatch-
OR
cisco8101-32hMatch-
OR
cisco8102-64hMatch-
OR
cisco8201Match-
OR
cisco8201-32fhMatch-
OR
cisco8202Match-
OR
cisco8804Match-
OR
cisco8808Match-
OR
cisco8812Match-
OR
cisco8818Match-
VendorProductVersionCPE
ciscoasr_9000v-v2-cpe:2.3:h:cisco:asr_9000v-v2:-:*:*:*:*:*:*:*
ciscoasr_9001-cpe:2.3:h:cisco:asr_9001:-:*:*:*:*:*:*:*
ciscoasr_9006-cpe:2.3:h:cisco:asr_9006:-:*:*:*:*:*:*:*
ciscoasr_9010-cpe:2.3:h:cisco:asr_9010:-:*:*:*:*:*:*:*
ciscoasr_9901-cpe:2.3:h:cisco:asr_9901:-:*:*:*:*:*:*:*
ciscoasr_9902-cpe:2.3:h:cisco:asr_9902:-:*:*:*:*:*:*:*
ciscoasr_9903-cpe:2.3:h:cisco:asr_9903:-:*:*:*:*:*:*:*
ciscoasr_9904-cpe:2.3:h:cisco:asr_9904:-:*:*:*:*:*:*:*
ciscoasr_9906-cpe:2.3:h:cisco:asr_9906:-:*:*:*:*:*:*:*
ciscoasr_9910-cpe:2.3:h:cisco:asr_9910:-:*:*:*:*:*:*:*
Rows per page:
1-10 of 461

CNA Affected

[
  {
    "product": "Cisco IOS XR Software",
    "vendor": "Cisco",
    "versions": [
      {
        "status": "affected",
        "version": "n/a"
      }
    ]
  }
]

CVSS2

7.2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:C/I:C/A:C

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

AI Score

7.4

Confidence

High

EPSS

0

Percentile

5.2%

Related for CVE-2021-34719