Lucene search

K
cvelistCertccCVELIST:CVE-2021-27853
HistorySep 27, 2022 - 12:00 a.m.

CVE-2021-27853 L2 network filtering can be bypassed using stacked VLAN0 and LLC/SNAP headers

2022-09-2700:00:00
CWE-290
certcc
www.cve.org
1
cve-2021-27853
network filtering
vlan0
llc/snap
bypass

5.2 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

26.6%

Layer 2 network filtering capabilities such as IPv6 RA guard or ARP inspection can be bypassed using combinations of VLAN 0 headers and LLC/SNAP headers.

CNA Affected

[
  {
    "vendor": "IEEE",
    "product": "802.2",
    "versions": [
      {
        "version": "802.2h-1997",
        "status": "affected",
        "lessThanOrEqual": "802.2h-1997",
        "versionType": "custom"
      }
    ]
  },
  {
    "vendor": "IETF",
    "product": "draft-ietf-v6ops-ra-guard",
    "versions": [
      {
        "version": "08",
        "status": "affected",
        "lessThanOrEqual": "08",
        "versionType": "custom"
      }
    ]
  },
  {
    "vendor": "IETF",
    "product": "P802.1Q",
    "versions": [
      {
        "version": "D1.0",
        "status": "affected",
        "lessThanOrEqual": "D1.0",
        "versionType": "custom"
      }
    ]
  }
]

5.2 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

26.6%

Related for CVELIST:CVE-2021-27853