Cisco IOS XR是美国思科(Cisco)公司的一套为其网络设备开发的操作系统。 Cisco IOS XR存在安全漏洞,该漏洞源于Cisco IOS XR 软件的 IP 服务级别协议 (IP SLA) 响应程序和双向主动测量协议 (TWAMP) 功能对套接字创建失败处理不当。攻击者可以通过向受影响的设备发送特定的 IP SLA 或 TWAMP 数据包来利用此漏洞。 漏洞可能允许未经身份验证的远程攻击者将设备数据包内存耗尽或导致 IP SLA 进程崩溃,导致拒绝服务 (DoS) 攻击。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Cisco | Cisco IOS XR Software | n/a | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2021-34718 | 8.1 HIGH | Cisco IOS XR Software Arbitrary File Read and Write Vulnerability |
| CVE-2021-34728 | 7.8 HIGH | Cisco IOS XR Software Authenticated User Privilege Escalation Vulnerabilities |
| CVE-2021-34719 | 7.8 HIGH | Cisco IOS XR Software Authenticated User Privilege Escalation Vulnerabilities |
| CVE-2021-34713 | 7.4 HIGH | Cisco IOS XR Software for ASR 9000 Series Routers Denial of Service Vulnerability |
| CVE-2021-34722 | 6.7 MEDIUM | Cisco IOS XR Software Command Injection Vulnerabilities |
| CVE-2021-34721 | 6.7 MEDIUM | Cisco IOS XR Software Command Injection Vulnerabilities |
| CVE-2021-34786 | 6.5 MEDIUM | Cisco BroadWorks CommPilot Application Software Vulnerabilities |
| CVE-2021-34785 | 6.5 MEDIUM | Cisco BroadWorks CommPilot Application Software Vulnerabilities |
| CVE-2021-34709 | 6.0 MEDIUM | Cisco IOS XR Software for Cisco 8000 and Network Convergence System 540 Series Routers Ima |
| CVE-2021-34708 | 6.0 MEDIUM | Cisco IOS XR Software for Cisco 8000 and Network Convergence System 540 Series Routers Ima |
| CVE-2021-34737 | 5.8 MEDIUM | Cisco IOS XR Software DHCP Version 4 Server Denial of Service Vulnerability |
| CVE-2021-34771 | 5.5 MEDIUM | Cisco IOS XR Software Unauthorized Information Disclosure Vulnerability |
No comments yet