5
CVSSv2

CVE-2021-1243

Published: 04/02/2021 Updated: 07/11/2023
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N

Vulnerability Summary

A vulnerability in the Local Packet Transport Services (LPTS) programming of the SNMP with the management plane protection feature of Cisco IOS XR Software could allow an unauthenticated, remote malicious user to allow connections despite the management plane protection that is configured to deny access to the SNMP server of an affected device. This vulnerability is due to incorrect LPTS programming when using SNMP with management plane protection. An attacker could exploit this vulnerability by connecting to an affected device using SNMP. A successful exploit could allow the malicious user to connect to the device on the configured SNMP ports. Valid credentials are required to execute any of the SNMP requests.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

cisco ios xr

cisco ios xr 7.0.11

cisco ios xr 6.7.1

cisco ios xr 7.2.0

cisco ios xr 7.1.0

Vendor Advisories

A vulnerability in the Local Packet Transport Services (LPTS) programming of the SNMP with the management plane protection feature of Cisco IOS XR Software could allow an unauthenticated, remote attacker to allow connections despite the management plane protection that is configured to deny access to the SNMP server of an affected device This vuln ...