CVE-2021-34718: Cisco IOS XR Software Arbitrary File Read and Write Vulnerability
A vulnerability in the SSH Server process of Cisco IOS XR Software could allow an authenticated, remote attacker to overwrite and read arbitrary files on the local device. This vulnerability is due to insufficient input validation of arguments that are supplied by the user for a specific file transfer method. An attacker with lower-level privileges could exploit this vulnerability by specifying Secure Copy Protocol (SCP) parameters when authenticating to a device. A successful exploit could allow the attacker to elevate their privileges and retrieve and upload files on a device that they should not have access to.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this Cisco IOS XR Software vulnerability?
The vulnerability ID is CVE-2021-34718.
What is the severity of CVE-2021-34718?
The severity of CVE-2021-34718 is high with a CVSS score of 8.1.
How does CVE-2021-34718 affect Cisco IOS XR Software?
CVE-2021-34718 allows an authenticated remote attacker to overwrite and read arbitrary files on the local device.
Which versions of Cisco IOS XR Software are affected by CVE-2021-34718?
Cisco IOS XR Software versions up to and including 7.3.2 are affected. Versions 7.4.0 and 7.4.1 are also affected.
How can CVE-2021-34718 be fixed?
To fix CVE-2021-34718, Cisco IOS XR Software users should apply the necessary updates provided by Cisco.