CVE-2021-34699 is a denial-of-service vulnerability affecting Cisco IOS and IOS XE Software, stemming from an improper interaction between the web UI and the TrustSec CLI parser. An authenticated, remote attacker can exploit this by requesting a specific CLI command via the web UI, causing the device to reload. Rated High severity (CVSS 7.7), this vulnerability has a low attack complexity and can lead to a significant service disruption. There is no public exploit code available, it is not listed in CISA's KEV catalog, and it has received no community discussion or media coverage, suggesting a low current exploitation risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
12.2\(6\)i1CPE matchmatch criteria | cpe:2.3:o:cisco:ios:12.2\(6\)i1:*:*:*:*:*:*:* | ||
15.0\(1\)syCPE matchmatch criteria | cpe:2.3:o:cisco:ios:15.0\(1\)sy:*:*:*:*:*:*:* | ||
15.0\(1\)sy1CPE matchmatch criteria | cpe:2.3:o:cisco:ios:15.0\(1\)sy1:*:*:*:*:*:*:* | ||
15.0\(1\)sy2CPE matchmatch criteria | cpe:2.3:o:cisco:ios:15.0\(1\)sy2:*:*:*:*:*:*:* | ||
15.0\(1\)sy3CPE matchmatch criteria | cpe:2.3:o:cisco:ios:15.0\(1\)sy3:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.