CVE-2021-34699CWE-435

Cisco IOS and IOS XE Software TrustSec CLI Parser Denial of Service Vulnerability

High · published September 23, 2021

CVSS v3.1
7.7
EPSS
1%
Percentile
65.8
In the wild
Unconfirmed
What it is

A vulnerability in the TrustSec CLI parser of Cisco IOS and Cisco IOS XE Software could allow an authenticated, remote attacker to cause an affected device to reload. This vulnerability is due to an improper interaction between the web UI and the CLI parser. An attacker could exploit this vulnerability by requesting a particular CLI command to be run through the web UI. A successful exploit could allow the attacker to cause the device to reload, resulting in a denial of service (DoS) condition.

The record
Technical detail
CVSS v3.1
7.7 · HIGH
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H
CVSS v4.0
Not supplied
EPSS
0.01187 · 65.8th percentile
Weakness
CWE-435 · Improper Interaction Between Multiple Correctly-Behaving Entities
Published
2021-09-23T02:25Z
EPSS history
Timeline
  • 23 SEP 02:25Z
    Cisco IOS and IOS XE Software TrustSec CLI Parser Denial of Service Vulnerability
    cvelistv5