5.8

CVE-2021-34696

Cisco ASR 900 and ASR 920 Series Aggregation Services Routers Access Control List Bypass Vulnerability

A vulnerability in the access control list (ACL) programming of Cisco ASR 900 and ASR 920 Series Aggregation Services Routers could allow an unauthenticated, remote attacker to bypass a configured ACL. This vulnerability is due to incorrect programming of hardware when an ACL is configured using a method other than the configuration CLI. An attacker could exploit this vulnerability by attempting to send traffic through an affected device. A successful exploit could allow the attacker to bypass an ACL on the affected device.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Cisco ≫ Ios Xe Version <= 17.3.2
   Cisco ≫ Asr 902 Version -
   Cisco ≫ Asr 903 Version -
   Cisco ≫ Asr 907 Version -
   Cisco ≫ Asr 920-10sz-pd Version -
   Cisco ≫ Asr 920-10sz-pd R Version -
   Cisco ≫ Asr 920-12cz-a Version -
   Cisco ≫ Asr 920-12cz-a R Version -
   Cisco ≫ Asr 920-12cz-d Version -
   Cisco ≫ Asr 920-12cz-d R Version -
   Cisco ≫ Asr 920-12sz-im Version -
   Cisco ≫ Asr 920-12sz-im R Version -
   Cisco ≫ Asr 920-24sz-im Version -
   Cisco ≫ Asr 920-24sz-im R Version -
   Cisco ≫ Asr 920-24sz-m Version -
   Cisco ≫ Asr 920-24sz-m R Version -
   Cisco ≫ Asr 920-24tz-m Version -
   Cisco ≫ Asr 920-24tz-m R Version -
   Cisco ≫ Asr 920-4sz-a Version -
   Cisco ≫ Asr 920-4sz-a R Version -
   Cisco ≫ Asr 920-4sz-d Version -
   Cisco ≫ Asr 920-4sz-d R Version -
   Cisco ≫ Asr 920u-12sz-im Version -
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1% 0.588
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 5.8 3.9 1.4
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N
NIST 5 10 2.9
AV:N/AC:L/Au:N/C:N/I:P/A:N
Cisco PSIRT 5.8 3.9 1.4
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N
CWE-284 Improper Access Control

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asr900acl-UeEyCxkv
Vendor Advisory