CVE-2021-34719: Cisco IOS XR Software Authenticated User Privilege Escalation Vulnerabilities
Multiple vulnerabilities in the CLI of Cisco IOS XR Software could allow an authenticated, local attacker with a low-privileged account to elevate privileges on an affected device. For more information about these vulnerabilities, see the Details section of this advisory.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-34719?
CVE-2021-34719 is a vulnerability in the CLI of Cisco IOS XR Software that could allow an authenticated, local attacker to elevate privileges on an affected device.
What is the severity of CVE-2021-34719?
The severity of CVE-2021-34719 is high, with a severity value of 7.8.
How does CVE-2021-34719 affect Cisco IOS XR Software?
CVE-2021-34719 affects Cisco IOS XR Software versions up to 7.3.2 and versions between 7.4.0 and 7.4.1.
How can an attacker exploit CVE-2021-34719?
An attacker with a low-privileged account can exploit CVE-2021-34719 by using the CLI of the affected device to elevate their privileges.
How can I fix CVE-2021-34719?
To fix CVE-2021-34719, upgrade Cisco IOS XR Software to a fixed version as mentioned in the advisory.