CVE-2021-34709

MEDIUM

Cisco IOS XR < 7.3.2 - Authenticated Arbitrary Code Execution via Image Verification Bypass

Title source: llm
STIX 2.1

Description

Multiple vulnerabilities in image verification checks of Cisco Network Convergence System (NCS) 540 Series Routers, only when running Cisco IOS XR NCS540L software images, and Cisco IOS XR Software for Cisco 8000 Series Routers could allow an authenticated, local attacker to execute arbitrary code on the underlying operating system. For more information about these vulnerabilities, see the Details section of this advisory.

References (1)

Core 1
Core References

Scores

CVSS v3 6.0
EPSS 0.0002
EPSS Percentile 6.9%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-347
Status published
Products (1)
cisco/ios_xr < 7.3.2
Published Sep 09, 2021
Tracked Since Feb 18, 2026