Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2021-1136


Multiple vulnerabilities in Cisco Network Convergence System (NCS) 540 Series Routers, only when running Cisco IOS XR NCS540L software images, and Cisco IOS XR Software for the Cisco 8000 Series Routers could allow an authenticated, local attacker to execute unsigned code during the boot process on an affected device. For more information about these vulnerabilities, see the Details section of this advisory.


Published

2021-02-04T17:15:14.467

Last Modified

2024-11-21T05:43:40.120

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 6.7 (MEDIUM)

CVSSv2 Vector

AV:L/AC:L/Au:N/C:P/I:P/A:P

  • Access Vector: LOCAL
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: PARTIAL
  • Availability Impact: PARTIAL
Exploitability Score

3.9

Impact Score

6.4

Weaknesses
  • Type: Primary
    CWE-347

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System cisco ios_xr < 7.0.12 Yes
Operating System cisco ios_xr < 7.2.1 Yes
Hardware cisco 8201 - No
Hardware cisco 8202 - No
Hardware cisco 8808 - No
Hardware cisco 8812 - No
Hardware cisco 8818 - No
Operating System cisco ios_xr < 7.2.1 Yes
Hardware cisco ncs_540 - No

References