Improper Verification of Cryptographic Signature in Cisco 8000 Series Routers and Cisco Network Convergence System 540 Series Routers - CVE-2021-34709

 

Improper Verification of Cryptographic Signature in Cisco 8000 Series Routers and Cisco Network Convergence System 540 Series Routers - CVE-2021-34709

Published: September 9, 2021


Vulnerability identifier: #VU56425
CSH Severity: Low
CVSS v4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-34709
CWE-ID: CWE-347
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local administrator to execute arbitrary code on the system. 

The vulnerability exists in the Cisco IOS XR due to a race condition that occurs when the install request is being processed. A local administrator can modify an ISO image and execute arbitrary code on the affected device. 


Affected software

Cisco 8000 Series Routers
Cisco Network Convergence System 540 Series Routers

How to mitigate CVE-2021-34709

Install updates from vendor's website.

Cisco 8000 Series Routers - addressed in versions 7.3.2, 7.3.15
Cisco Network Convergence System 540 Series Routers - addressed in versions 7.3.2, 7.4.1

External References

Related Security Bulletins