PT-2021-4846 · Cisco · Cisco Ios Xe Wireless Controller+1

Luke Jenkins

·

Published

2021-09-22

·

Updated

2025-10-30

·

CVE-2021-34767

CVSS v3.1

7.4

High

VectorAV:A/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Cisco IOS XE Wireless Controller Software for Cisco Catalyst 9000 Family Wireless Controllers (affected versions not specified)
Description A logic error in the processing of specific link-local IPv6 traffic could allow an unauthenticated, adjacent attacker to cause a Layer 2 (L2) loop in a configured VLAN, resulting in a denial of service (DoS) condition for that VLAN. An attacker could exploit this issue by sending a crafted IPv6 packet that would flow inbound through the wired interface of an affected device, potentially causing traffic drops in the affected VLAN and triggering the DoS condition.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2021-05574
CVE-2021-34767

Affected Products

Cisco Ios Xe Wireless Controller
Cisco Ios Xe