A vulnerability in the vDaemon process in Cisco IOS XE SD-WAN Software could allow an unauthenticated, remote attacker to cause a buffer overflow on an affected device. This vulnerability is due to insufficient bounds checking when an affected device processes traffic. An attacker could exploit this vulnerability by sending crafted traffic to the device. A successful exploit could allow the attacker to cause a buffer overflow and possibly execute arbitrary commands with root-level privileges, or cause the device to reload, which could result in a denial of service condition.
Project Subscriptions
| Vendors | Products |
|---|---|
|
Cisco
Subscribe
|
1000 Integrated Services Router
Subscribe
1100-4g\/6g Integrated Services Router
Subscribe
1100-4p Integrated Services Router
Subscribe
1100-8p Integrated Services Router
Subscribe
1100 Integrated Services Router
Subscribe
1101-4p Integrated Services Router
Subscribe
1101 Integrated Services Router
Subscribe
1109-2p Integrated Services Router
Subscribe
1109-4p Integrated Services Router
Subscribe
1109 Integrated Services Router
Subscribe
1111x-8p Integrated Services Router
Subscribe
1111x Integrated Services Router
Subscribe
111x Integrated Services Router
Subscribe
1120 Integrated Services Router
Subscribe
1160 Integrated Services Router
Subscribe
4000 Integrated Services Router
Subscribe
4221 Integrated Services Router
Subscribe
422 Integrated Services Router
Subscribe
4321 Integrated Services Router
Subscribe
4331 Integrated Services Router
Subscribe
4351 Integrated Services Router
Subscribe
4431 Integrated Services Router
Subscribe
4451-x Integrated Services Router
Subscribe
4451 Integrated Services Router
Subscribe
4461 Integrated Services Router
Subscribe
Asr 1000
Subscribe
Asr 1000-esp100
Subscribe
Asr 1000-x
Subscribe
Asr 1000 Series
Subscribe
Asr 1000 Series Route Processor \(rp2\)
Subscribe
Asr 1000 Series Route Processor \(rp3\)
Subscribe
Asr 1001
Subscribe
Asr 1001-hx
Subscribe
Asr 1001-hx R
Subscribe
Asr 1001-x
Subscribe
Asr 1001-x R
Subscribe
Asr 1002
Subscribe
Asr 1002-hx
Subscribe
Asr 1002-hx R
Subscribe
Asr 1002-x
Subscribe
Asr 1002-x R
Subscribe
Asr 1004
Subscribe
Asr 1006
Subscribe
Asr 1006-x
Subscribe
Asr 1009-x
Subscribe
Asr 1013
Subscribe
Asr 1023
Subscribe
Csr 1000v
Subscribe
Ios Xe Sd-wan
Subscribe
|
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-21377 | A vulnerability in the vDaemon process in Cisco IOS XE SD-WAN Software could allow an unauthenticated, remote attacker to cause a buffer overflow on an affected device. This vulnerability is due to insufficient bounds checking when an affected device processes traffic. An attacker could exploit this vulnerability by sending crafted traffic to the device. A successful exploit could allow the attacker to cause a buffer overflow and possibly execute arbitrary commands with root-level privileges, or cause the device to reload, which could result in a denial of service condition. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Thu, 07 Nov 2024 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: cisco
Published:
Updated: 2024-11-07T21:58:32.363Z
Reserved: 2021-06-15T00:00:00
Link: CVE-2021-34727
Updated: 2024-08-04T00:19:48.130Z
Status : Modified
Published: 2021-09-23T03:15:19.500
Modified: 2024-11-21T06:11:03.730
Link: CVE-2021-34727
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD