CVE-2021-34770 is a critical vulnerability in the CAPWAP protocol processing of Cisco IOS XE Software for Cisco Catalyst 9000 Family Wireless Controllers. An unauthenticated, remote attacker can exploit a logic error by sending a crafted CAPWAP packet. This allows for arbitrary code execution with administrative privileges or a denial of service (DoS) condition, evidenced by its CVSS score of 9.8 (CRITICAL). While there is no known active exploitation or public exploit code (Metasploit, Nuclei, ExploitDB), the vulnerability has garnered significant community discussion and media coverage, indicating high awareness.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:cisco:ios_xe:-:*:*:*:*:*:*:* | ||
3.15.1xbsCPE matchmatch criteria | cpe:2.3:o:cisco:ios_xe:3.15.1xbs:*:*:*:*:*:*:* | ||
3.15.2xbsCPE matchmatch criteria | cpe:2.3:o:cisco:ios_xe:3.15.2xbs:*:*:*:*:*:*:* | ||
16.6.4sCPE matchmatch criteria | cpe:2.3:o:cisco:ios_xe:16.6.4s:*:*:*:*:*:*:* | ||
16.10.1CPE matchmatch criteria | cpe:2.3:o:cisco:ios_xe:16.10.1:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.