CVE-2021-1243
Cisco IOS XR Software SNMP Management Plane Protection ACL Bypass Vulnerability
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
A vulnerability in the Local Packet Transport Services (LPTS) programming of the SNMP with the management plane protection feature of Cisco IOS XR Software could allow an unauthenticated, remote attacker to allow connections despite the management plane protection that is configured to deny access to the SNMP server of an affected device. This vulnerability is due to incorrect LPTS programming when using SNMP with management plane protection. An attacker could exploit this vulnerability by connecting to an affected device using SNMP. A successful exploit could allow the attacker to connect to the device on the configured SNMP ports. Valid credentials are required to execute any of the SNMP requests.
Una vulnerabilidad en la programación Local Packet Transport Services (LPTS) del SNMP con la funcionalidad de protección del plano de administración del Software Cisco IOS XR, podría permitir a un atacante remoto no autenticado habilitar conexiones a pesar de la protección del plano de administración que está configurada para denegar el acceso al servidor SNMP de un dispositivo afectado. Esta vulnerabilidad es debido a una programación LPTS incorrecta cuando se usa SNMP con protección del plano de administración. Un atacante podría explotar esta vulnerabilidad al conectar a un dispositivo afectado usando SNMP. Una explotación con éxito podría permitir al atacante conectarse al dispositivo en los puertos SNMP configurados. Las credenciales válidas son requeridas para ejecutar cualquiera de las peticiones SNMP
CVSS Scores
SSVC
- Decision:Attend
Timeline
- 2020-11-13 CVE Reserved
- 2021-02-04 CVE Published
- 2024-02-08 EPSS Updated
- 2024-11-08 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-284: Improper Access Control
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-snmp-7MKrW7Nq | 2023-11-07 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Cisco Search vendor "Cisco" | Ios Xr Search vendor "Cisco" for product "Ios Xr" | > 6.1.1 < 6.6.4 Search vendor "Cisco" for product "Ios Xr" and version " > 6.1.1 < 6.6.4" | - |
Affected
| ||||||
Cisco Search vendor "Cisco" | Ios Xr Search vendor "Cisco" for product "Ios Xr" | >= 7.0.0 < 7.0.2 Search vendor "Cisco" for product "Ios Xr" and version " >= 7.0.0 < 7.0.2" | - |
Affected
| ||||||
Cisco Search vendor "Cisco" | Ios Xr Search vendor "Cisco" for product "Ios Xr" | 6.7.1 Search vendor "Cisco" for product "Ios Xr" and version "6.7.1" | - |
Affected
| ||||||
Cisco Search vendor "Cisco" | Ios Xr Search vendor "Cisco" for product "Ios Xr" | 7.0.11 Search vendor "Cisco" for product "Ios Xr" and version "7.0.11" | - |
Affected
| ||||||
Cisco Search vendor "Cisco" | Ios Xr Search vendor "Cisco" for product "Ios Xr" | 7.1.0 Search vendor "Cisco" for product "Ios Xr" and version "7.1.0" | - |
Affected
| ||||||
Cisco Search vendor "Cisco" | Ios Xr Search vendor "Cisco" for product "Ios Xr" | 7.2.0 Search vendor "Cisco" for product "Ios Xr" and version "7.2.0" | - |
Affected
|