CVE-2021-34705

MEDIUM

Cisco IOS - Unauthenticated Destination Pattern Bypass via Malformed Dial String

Title source: llm
STIX 2.1

Description

A vulnerability in the Voice Telephony Service Provider (VTSP) service of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to bypass configured destination patterns and dial arbitrary numbers. This vulnerability is due to insufficient validation of dial strings at Foreign Exchange Office (FXO) interfaces. An attacker could exploit this vulnerability by sending a malformed dial string to an affected device via either the ISDN protocol or SIP. A successful exploit could allow the attacker to conduct toll fraud, resulting in unexpected financial impact to affected customers.

References (1)

Core 1

Scores

CVSS v3 5.3
EPSS 0.0055
EPSS Percentile 68.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

Details

CWE
CWE-232
Status published
Products (50)
cisco/ios 12.3\(7\)xm
cisco/ios 12.3\(7\)xr
cisco/ios 12.3\(7\)xr1
cisco/ios 12.3\(7\)xr2
cisco/ios 12.3\(7\)xr3
cisco/ios 12.3\(7\)xr4
cisco/ios 12.3\(7\)xr5
cisco/ios 12.3\(7\)xr6
cisco/ios 12.3\(7\)xr7
cisco/ios 12.3\(8\)ja2
... and 40 more
Published Sep 23, 2021
Tracked Since Feb 18, 2026