CVE-2021-1244

MEDIUM

Cisco IOS XR < 7.0.12 - Authenticated Unsigned Code Execution during Boot Process

Title source: llm
STIX 2.1

Description

Multiple vulnerabilities in Cisco Network Convergence System (NCS) 540 Series Routers, only when running Cisco IOS XR NCS540L software images, and Cisco IOS XR Software for the Cisco 8000 Series Routers could allow an authenticated, local attacker to execute unsigned code during the boot process on an affected device. For more information about these vulnerabilities, see the Details section of this advisory.

References (1)

Core 1
Core References

Scores

CVSS v3 6.7
EPSS 0.0002
EPSS Percentile 6.8%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-347
Status published
Products (1)
cisco/ios_xr < 7.0.12
Published Feb 04, 2021
Tracked Since Feb 18, 2026