PT-2022-4863 · Cisco · Cisco Ios+1

Etienne Champetier

·

Published

2022-09-27

·

Updated

2022-11-16

·

CVE-2021-27853

CVSS v3.1

4.7

Medium

VectorAV:A/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions No specific software or versions are mentioned in the provided descriptions.
Description The issue is related to the implementation of the Ethernet encapsulation protocol, specifically concerning the combination of headers. This could allow a remote attacker to cause a denial of service or implement a man-in-the-middle (MITM) attack. Layer 2 network filtering capabilities, such as IPv6 RA guard or ARP inspection, can be bypassed using combinations of VLAN 0 headers and LLC/SNAP headers.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

DoS

Authentication Bypass by Spoofing

Weakness Enumeration

Related Identifiers

BDU:2022-05987
CVE-2021-27853

Affected Products

Cisco Ios
Cisco Nexus