Cisco IOS XR是美国思科(Cisco)公司的一套为其网络设备开发的操作系统。 Cisco IOS XR软件的DHCP服务器功能(DHCPv4版本)存在代码问题漏洞,该漏洞源于某些DHCPv4消息在受影响的设备处理时未经正确验证。攻击者可利用该漏洞通过向受影响的设备发送格式错误的DHCPv4消息导致空指针解引用,从而导致系统崩溃
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Cisco | Cisco IOS XR Software | n/a | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2021-34720 | 8.6 HIGH | Cisco IOS XR Software IP Service Level Agreements and Two-Way Active Measurement Protocol |
| CVE-2021-34718 | 8.1 HIGH | Cisco IOS XR Software Arbitrary File Read and Write Vulnerability |
| CVE-2021-34728 | 7.8 HIGH | Cisco IOS XR Software Authenticated User Privilege Escalation Vulnerabilities |
| CVE-2021-34719 | 7.8 HIGH | Cisco IOS XR Software Authenticated User Privilege Escalation Vulnerabilities |
| CVE-2021-34713 | 7.4 HIGH | Cisco IOS XR Software for ASR 9000 Series Routers Denial of Service Vulnerability |
| CVE-2021-34722 | 6.7 MEDIUM | Cisco IOS XR Software Command Injection Vulnerabilities |
| CVE-2021-34721 | 6.7 MEDIUM | Cisco IOS XR Software Command Injection Vulnerabilities |
| CVE-2021-34786 | 6.5 MEDIUM | Cisco BroadWorks CommPilot Application Software Vulnerabilities |
| CVE-2021-34785 | 6.5 MEDIUM | Cisco BroadWorks CommPilot Application Software Vulnerabilities |
| CVE-2021-34709 | 6.0 MEDIUM | Cisco IOS XR Software for Cisco 8000 and Network Convergence System 540 Series Routers Ima |
| CVE-2021-34708 | 6.0 MEDIUM | Cisco IOS XR Software for Cisco 8000 and Network Convergence System 540 Series Routers Ima |
| CVE-2021-34771 | 5.5 MEDIUM | Cisco IOS XR Software Unauthorized Information Disclosure Vulnerability |
No comments yet