CVE-2021-1451: Cisco IOS XE Software Easy Virtual Switching System Arbitrary Code Execution Vulnerability
A vulnerability in the Easy Virtual Switching System (VSS) feature of Cisco IOS XE Software for Cisco Catalyst 4500 Series Switches and Cisco Catalyst 4500-X Series Switches could allow an unauthenticated, remote attacker to execute arbitrary code on the underlying Linux operating system of an affected device. The vulnerability is due to incorrect boundary checks of certain values in Easy VSS protocol packets that are destined for an affected device. An attacker could exploit this vulnerability by sending crafted Easy VSS protocol packets to UDP port 5500 while the affected device is in a specific state. When the crafted packet is processed, a buffer overflow condition may occur. A successful exploit could allow the attacker to trigger a denial of service (DoS) condition or execute arbitrary code with root privileges on the underlying Linux operating system of the affected device.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-1451?
CVE-2021-1451 has a severity rating of critical due to the potential for remote code execution.
How do I fix CVE-2021-1451?
To fix CVE-2021-1451, upgrade the affected Cisco IOS XE software to a version that mitigates the vulnerability.
What systems are affected by CVE-2021-1451?
CVE-2021-1451 affects multiple versions of Cisco IOS XE software running on Cisco Catalyst 4500 Series and 4500-X Series switches.
Is CVE-2021-1451 exploitable without authentication?
Yes, CVE-2021-1451 can be exploited by an unauthenticated remote attacker.
What is the potential impact of CVE-2021-1451?
The potential impact of CVE-2021-1451 includes the ability for an attacker to execute arbitrary code on vulnerable devices.