CVE-2021-34705: Cisco IOS and IOS XE Software FXO Interface Destination Pattern Bypass Vulnerability
A vulnerability in the Voice Telephony Service Provider (VTSP) service of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to bypass configured destination patterns and dial arbitrary numbers. This vulnerability is due to insufficient validation of dial strings at Foreign Exchange Office (FXO) interfaces. An attacker could exploit this vulnerability by sending a malformed dial string to an affected device via either the ISDN protocol or SIP. A successful exploit could allow the attacker to conduct toll fraud, resulting in unexpected financial impact to affected customers.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-34705?
CVE-2021-34705 is rated as high severity because it allows unauthenticated attackers to bypass security measures.
How do I fix CVE-2021-34705?
To mitigate CVE-2021-34705, upgrade affected Cisco IOS Software or Cisco IOS XE Software to the recommended versions as specified in the security advisory.
Which Cisco products are affected by CVE-2021-34705?
CVE-2021-34705 affects various versions of Cisco IOS Software and Cisco IOS XE Software.
What kind of attack does CVE-2021-34705 enable?
CVE-2021-34705 enables remote attackers to bypass configured destination patterns and dial arbitrary numbers.
Is authentication required to exploit CVE-2021-34705?
No, CVE-2021-34705 can be exploited by unauthenticated attackers.