CVE-2021-34728: Cisco IOS XR Software Authenticated User Privilege Escalation Vulnerabilities
Multiple vulnerabilities in the CLI of Cisco IOS XR Software could allow an authenticated, local attacker with a low-privileged account to elevate privileges on an affected device. For more information about these vulnerabilities, see the Details section of this advisory.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-34728?
CVE-2021-34728 is a vulnerability in the CLI of Cisco IOS XR Software that could allow an authenticated, local attacker to elevate privileges on an affected device.
What is the severity of CVE-2021-34728?
The severity of CVE-2021-34728 is high with a CVSS score of 7.8.
How can an attacker exploit CVE-2021-34728?
An attacker with a low-privileged account can exploit CVE-2021-34728 by leveraging vulnerabilities in the CLI of Cisco IOS XR Software to elevate privileges on the targeted device.
Which versions of Cisco IOS XR Software are affected by CVE-2021-34728?
Cisco IOS XR Software versions up to and including 7.3.2 and versions 7.4.0 to 7.4.1 are affected by CVE-2021-34728.
How can I mitigate the CVE-2021-34728 vulnerability?
To mitigate the CVE-2021-34728 vulnerability, Cisco recommends upgrading to a fixed software release.