CVE-2021-34713
A vulnerability in the Layer 2 punt code of Cisco IOS XR Software running on Cisco ASR 9000 Series Aggregation Services Routers could allow an unauthenticated, adjacent attacker to cause the affected line card to reboot. This vulnerability is due to incorrect handling of specific Ethernet frames that cause a spin loop that can make the network processors unresponsive. An attacker could exploit this vulnerability by sending specific types of Ethernet frames on the segment where the affected line cards are attached. A successful exploit could allow the attacker to cause the affected line card to reboot.
Published:Sep 9, 2021
Last Modified:Nov 21, 2024
EPS:Sep 9, 2021
EPSS Score:0.00101
CVSS Score:7.4
Affected Products
Vendor
Product
Action
Vendor
Cisco
Product
Asr 9000
Cisco
Asr 9000
Vendor
Cisco
Product
Asr 9000v-v2
Cisco
Asr 9000v-v2
Vendor
Cisco
Product
Asr 9001
Cisco
Asr 9001
Vendor
Cisco
Product
Asr 9006
Cisco
Asr 9006
Vendor
Cisco
Product
Asr 9010
Cisco
Asr 9010
Vendor
Cisco
Product
Asr 9901
Cisco
Asr 9901
Vendor
Cisco
Product
Asr 9902
Cisco
Asr 9902
Vendor
Cisco
Product
Asr 9903
Cisco
Asr 9903
Vendor
Cisco
Product
Asr 9904
Cisco
Asr 9904
Vendor
Cisco
Product
Asr 9906
Cisco
Asr 9906
Vendor
Cisco
Product
Asr 9910
Cisco
Asr 9910
Vendor
Cisco
Product
Asr 9912
Cisco
Asr 9912
Vendor
Cisco
Product
Asr 9922
Cisco
Asr 9922
Vendor
Cisco
Product
Ios Xr
Cisco
Ios Xr
Exploits
No exploit reference
Common Weakness Enumeration
No CWE recorded yet
Common Attack Pattern Enumeration and Classification (CAPEC)
No CAPEC recorded yet
Related CVEs
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
