CVE-2021-34718 is a high-severity vulnerability in the SSH Server process of Cisco IOS XR Software, allowing an authenticated, remote attacker to read and write arbitrary files. This flaw stems from insufficient input validation of SCP parameters, enabling an attacker with lower-level privileges to elevate their access and manipulate files. The vulnerability has a CVSS score of 8.1 (High) due to its network attack vector, low attack complexity, and high impact on confidentiality and integrity. While no public exploit code or active exploitation has been reported, it has garnered some community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 7.3.2CPE matchmatch criteria | cpe:2.3:o:cisco:ios_xr:*:*:*:*:*:*:*:* | ||
>= 7.4.0, < 7.4.1CPE matchmatch criteria | cpe:2.3:o:cisco:ios_xr:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.