CVE-2021-34767: Cisco IOS XE Software for Catalyst 9800 Series Wireless Controllers IPv6 Denial of Service Vulnerability
A vulnerability in IPv6 traffic processing of Cisco IOS XE Wireless Controller Software for Cisco Catalyst 9000 Family Wireless Controllers could allow an unauthenticated, adjacent attacker to cause a Layer 2 (L2) loop in a configured VLAN, resulting in a denial of service (DoS) condition for that VLAN. The vulnerability is due to a logic error when processing specific link-local IPv6 traffic. An attacker could exploit this vulnerability by sending a crafted IPv6 packet that would flow inbound through the wired interface of an affected device. A successful exploit could allow the attacker to cause traffic drops in the affected VLAN, thus triggering the DoS condition.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-34767?
CVE-2021-34767 has a CVSS score indicating a critical severity level due to the potential for Denial of Service.
How do I fix CVE-2021-34767?
To fix CVE-2021-34767, you should upgrade your Cisco IOS XE software to the latest patched version provided by Cisco.
What impact does CVE-2021-34767 have on affected systems?
CVE-2021-34767 can lead to a Layer 2 loop within a VLAN, resulting in service interruption or Denial of Service.
Which Cisco devices are affected by CVE-2021-34767?
CVE-2021-34767 affects various versions of Cisco IOS XE running on Catalyst 9000 Family Wireless Controllers.
Can an attacker exploit CVE-2021-34767 remotely?
No, CVE-2021-34767 requires an unauthenticated, adjacent attacker to exploit the vulnerability.