CVE-2021-27861
L2 network filtering bypass using stacked VLAN0 and LLC/SNAP headers with invalid lengths
Severity Score
4.7
*CVSS v3.1
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
0
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
-
*SSVC
Descriptions
Layer 2 network filtering capabilities such as IPv6 RA guard can be bypassed using LLC/SNAP headers with invalid length (and optionally VLAN0 headers)
Las capacidades de filtrado de red de capa 2, como la protección RA de IPv6, pueden omitirse usando encabezados LLC/SNAP con una longitud no válida (y, opcionalmente, encabezados VLAN0)
*Credits:
Etienne Champetier (@champtar) <champetier.etienne@gmail.com>
CVSS Scores
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2021-03-01 CVE Reserved
- 2022-09-27 CVE Published
- 2024-04-19 EPSS Updated
- 2024-09-16 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-130: Improper Handling of Length Parameter Inconsistency
- CWE-290: Authentication Bypass by Spoofing
CAPEC
References (5)
URL | Tag | Source |
---|---|---|
https://blog.champtar.fr/VLAN0_LLC_SNAP | ||
https://datatracker.ietf.org/doc/draft-ietf-v6ops-ra-guard/08 | Third Party Advisory | |
https://kb.cert.org/vuls/id/855201 | ||
https://standards.ieee.org/ieee/802.1Q/10323 | Third Party Advisory | |
https://standards.ieee.org/ieee/802.2/1048 | Third Party Advisory |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Ieee Search vendor "Ieee" | Ieee 802.2 Search vendor "Ieee" for product "Ieee 802.2" | <= 802.2h-1997 Search vendor "Ieee" for product "Ieee 802.2" and version " <= 802.2h-1997" | - |
Affected
| ||||||
Ietf Search vendor "Ietf" | P802.1q Search vendor "Ietf" for product "P802.1q" | <= d1.0 Search vendor "Ietf" for product "P802.1q" and version " <= d1.0" | - |
Affected
|