Vulnslist

find the latest Cisco vulnerabilities

Cisco IOS XR Software Unauthorized Information Disclosure Vulnerability

cisco-sa-iosxr-infodisc-CjLdGMc5 · Medium · Published · Updated

A vulnerability in the Cisco IOS XR Software CLI could allow an authenticated, local attacker to view more information than their privileges allow. This vulnerability is due to insufficient application of restrictions during the execution of a specific command. An attacker could exploit this vulnerability by running a specific command. A successful exploit could allow the attacker to view sensitive configuration information that their privileges might not otherwise allow them to access. Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability. This advisory is available at the following link:https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-iosxr-infodisc-CjLdGMc5 This advisory is part of the September 2021 release of the Cisco IOS XR Software Security Advisory Bundled Publication. For a complete list of the advisories and links to them, see Cisco Event Response: September 2021 Cisco IOS XR Software Security Advisory Bundled Publication.

Workarounds

There are no workarounds that address this vulnerability.

CVEsCVE-2021-34771
Cisco Bug IDsCSCvy33646
CVSS ScoreBase 5.5
Base 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N/E:X/RL:X/RC:X
Product Names From Source
Cisco IOS XR Software

Related Products

Product CVE Evidence
Cisco Nexus Dashboard CVE-2021-34771 Cisco OpenVuln
Cisco IOS Software CVE-2021-34771 Cisco OpenVuln
Cisco Catalyst PON Series Switches CVE-2021-34771 Cisco OpenVuln
Cisco IOS XR Software CVE-2021-34771 Cisco OpenVuln
Cisco IOS CVE-2021-34771 Cisco OpenVuln