CVE-2021-34721: Cisco IOS XR Software Command Injection Vulnerabilities
Multiple vulnerabilities in the CLI of Cisco IOS XR Software could allow an authenticated, local attacker to gain access to the underlying root shell of an affected device and execute arbitrary commands with root privileges. For more information about these vulnerabilities, see the Details section of this advisory.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-34721?
The severity of CVE-2021-34721 is medium.
How can an attacker exploit CVE-2021-34721?
An attacker can exploit CVE-2021-34721 by gaining access to the underlying root shell of an affected device and executing arbitrary commands with root privileges.
Which versions of Cisco IOS XR Software are affected by CVE-2021-34721?
Versions up to 7.3.2 and versions between 7.4.0 and 7.4.1 of Cisco IOS XR Software are affected by CVE-2021-34721.
Is Cisco Asr 9000v-v2 vulnerable to CVE-2021-34721?
No, Cisco Asr 9000v-v2 is not vulnerable to CVE-2021-34721.
Where can I find more information about CVE-2021-34721?
You can find more information about CVE-2021-34721 on the Cisco Security Advisory page.