CVE-2021-34699: Cisco IOS and IOS XE Software TrustSec CLI Parser Denial of Service Vulnerability
A vulnerability in the TrustSec CLI parser of Cisco IOS and Cisco IOS XE Software could allow an authenticated, remote attacker to cause an affected device to reload. This vulnerability is due to an improper interaction between the web UI and the CLI parser. An attacker could exploit this vulnerability by requesting a particular CLI command to be run through the web UI. A successful exploit could allow the attacker to cause the device to reload, resulting in a denial of service (DoS) condition.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-34699?
CVE-2021-34699 has a CVSS score of 7.5, indicating a high severity remote denial of service vulnerability.
How do I fix CVE-2021-34699?
To fix CVE-2021-34699, update the affected Cisco IOS or IOS XE software to the latest available version.
Who is affected by CVE-2021-34699?
CVE-2021-34699 affects multiple versions of Cisco IOS and Cisco IOS XE software across a range of Cisco devices.
What kind of attack exploits CVE-2021-34699?
An authenticated remote attacker can exploit CVE-2021-34699 to cause a denial of service by manipulating the TrustSec CLI parser.
Is there a workaround for CVE-2021-34699?
Currently, no specific workaround is provided for CVE-2021-34699; applying the appropriate software updates is recommended.