CVE-2021-34705
MEDIUMCisco IOS - Unauthenticated Destination Pattern Bypass via Malformed Dial String
Title source: llmDescription
A vulnerability in the Voice Telephony Service Provider (VTSP) service of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to bypass configured destination patterns and dial arbitrary numbers. This vulnerability is due to insufficient validation of dial strings at Foreign Exchange Office (FXO) interfaces. An attacker could exploit this vulnerability by sending a malformed dial string to an affected device via either the ISDN protocol or SIP. A successful exploit could allow the attacker to conduct toll fraud, resulting in unexpected financial impact to affected customers.
References (1)
Core 1
Core References
Vendor Advisory vendor-advisory
x_refsource_cisco
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fxo-pattern-bypass-jUXgygYv
Scores
CVSS v3
5.3
EPSS
0.0055
EPSS Percentile
68.2%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Details
CWE
CWE-232
Status
published
Products (50)
cisco/ios
12.3\(7\)xm
cisco/ios
12.3\(7\)xr
cisco/ios
12.3\(7\)xr1
cisco/ios
12.3\(7\)xr2
cisco/ios
12.3\(7\)xr3
cisco/ios
12.3\(7\)xr4
cisco/ios
12.3\(7\)xr5
cisco/ios
12.3\(7\)xr6
cisco/ios
12.3\(7\)xr7
cisco/ios
12.3\(8\)ja2
... and 40 more
Published
Sep 23, 2021
Tracked Since
Feb 18, 2026