9.8
CVSSv3

CVE-2021-1451

Published: 24/03/2021 Updated: 07/11/2023
CVSS v2 Base Score: 9.3 | Impact Score: 10 | Exploitability Score: 8.6
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 828
Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

A vulnerability in the Easy Virtual Switching System (VSS) feature of Cisco IOS XE Software for Cisco Catalyst 4500 Series Switches and Cisco Catalyst 4500-X Series Switches could allow an unauthenticated, remote malicious user to execute arbitrary code on the underlying Linux operating system of an affected device. The vulnerability is due to incorrect boundary checks of certain values in Easy VSS protocol packets that are destined for an affected device. An attacker could exploit this vulnerability by sending crafted Easy VSS protocol packets to UDP port 5500 while the affected device is in a specific state. When the crafted packet is processed, a buffer overflow condition may occur. A successful exploit could allow the malicious user to trigger a denial of service (DoS) condition or execute arbitrary code with root privileges on the underlying Linux operating system of the affected device.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

cisco ios_xe 3.6.0be

cisco ios_xe 3.6.0e

cisco ios_xe 3.6.1e

cisco ios_xe 3.6.2e

cisco ios_xe 3.6.3e

cisco ios_xe 3.6.4e

cisco ios_xe 3.6.5ae

cisco ios_xe 3.6.5be

cisco ios_xe 3.6.5e

cisco ios_xe 3.6.6e

cisco ios_xe 3.6.7e

cisco ios_xe 3.6.8e

cisco ios_xe 3.6.9e

cisco ios_xe 3.6.10e

cisco ios_xe 3.7.0e

cisco ios_xe 3.7.1e

cisco ios_xe 3.7.2e

cisco ios_xe 3.7.3e

cisco ios_xe 3.7.4e

cisco ios_xe 3.7.5e

cisco ios_xe 3.8.0e

cisco ios_xe 3.8.1e

cisco ios_xe 3.8.2e

cisco ios_xe 3.8.3e

cisco ios_xe 3.8.4e

cisco ios_xe 3.8.5ae

cisco ios_xe 3.8.5e

cisco ios_xe 3.8.6e

cisco ios_xe 3.8.7e

cisco ios_xe 3.8.8e

cisco ios_xe 3.8.9e

cisco ios_xe 3.8.10e

cisco ios_xe 3.9.0e

cisco ios_xe 3.9.1e

cisco ios_xe 3.9.2be

cisco ios_xe 3.9.2e

cisco ios_xe 3.10.0ce

cisco ios_xe 3.10.0e

cisco ios_xe 3.10.1ae

cisco ios_xe 3.10.1e

cisco ios_xe 3.10.1se

cisco ios_xe 3.10.2e

cisco ios_xe 3.10.3e

cisco ios_xe 3.11.0e

cisco ios_xe 3.11.1ae

cisco ios_xe 3.11.1e

cisco ios_xe 3.11.2ae

cisco ios_xe 3.11.2e

cisco ios_xe 3.11.3ae

cisco ios_xe 3.11.3e

cisco ios_xe 15.2\\(7\\)e

cisco ios_xe 16.11.2

cisco ios_xe 16.12.5a

cisco ios_xe 17.3.1

Vendor Advisories

A vulnerability in the Easy Virtual Switching System (VSS) feature of Cisco IOS XE Software for Cisco Catalyst 4500 Series Switches and Cisco Catalyst 4500-X Series Switches could allow an unauthenticated, remote attacker to execute arbitrary code on the underlying Linux operating system of an affected device The vulnerability is due to incorrect ...