First published: Tue Sep 27 2022(Updated: )
Layer 2 network filtering capabilities such as IPv6 RA guard can be bypassed using LLC/SNAP headers with invalid length (and optionally VLAN0 headers)
Credit: cret@cert.org
Affected Software | Affected Version | How to fix |
---|---|---|
Ieee Ieee 802.2 | <=802.2h-1997 | |
Ietf P802.1q | <=d1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-27861 is a vulnerability that allows bypassing layer 2 network filtering capabilities such as IPv6 RA guard by using LLC/SNAP headers with invalid length.
The layer 2 network filtering capabilities can be bypassed by using LLC/SNAP headers with invalid length and optionally VLAN0 headers.
The vulnerability affects IEEE 802.2 (up to and including version 802.2h-1997) and IETF P802.1q (up to and including version d1.0).
The severity of CVE-2021-27861 is medium with a severity value of 4.7.
To fix CVE-2021-27861, it is recommended to update the affected software to a version that addresses the vulnerability.