CVE-2021-34770 Details
Description
A vulnerability in the Control and Provisioning of Wireless Access Points (CAPWAP) protocol processing of Cisco IOS XE Software for Cisco Catalyst 9000 Family Wireless Controllers could allow an unauthenticated, remote attacker to execute arbitrary code with administrative privileges or cause a denial of service (DoS) condition on an affected device. The vulnerability is due to a logic error that occurs during the validation of CAPWAP packets. An attacker could exploit this vulnerability by sending a crafted CAPWAP packet to an affected device. A successful exploit could allow the attacker to execute arbitrary code with administrative privileges or cause the affected device to crash and reload, resulting in a DoS condition.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Nov 7, 2024References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-787 | Out-of-bounds Write | [email protected] |
| CWE-122 | Heap-based Buffer Overflow | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| cisco ios xe | 3.15.1xbs 3.15.2xbs 16.6.4s 16.10.1 16.10.1e 16.10.1s 16.11.1 16.11.1a 16.11.1b 16.11.1c 16.11.2 16.12.1 16.12.1s 16.12.1t 16.12.2s 16.12.2t 16.12.3 16.12.3s 16.12.4 16.12.4a 17.1.1 17.1.1s 17.1.1t 17.1.2 17.1.3 17.2.1 17.2.1a 17.3.1 |
CPE
Remediation
| |
| cisco catalyst 9800 | All versions |
CPE
Remediation
| |
| cisco catalyst 9800-40 | All versions |
CPE
Remediation
| |
| cisco catalyst 9800-40 wireless controller | All versions |
CPE
Remediation
| |
| cisco catalyst 9800-80 | All versions |
CPE
Remediation
| |
| cisco catalyst 9800-80 wireless controller | All versions |
CPE
Remediation
| |
| cisco catalyst 9800-cl | All versions |
CPE
Remediation
| |
| cisco catalyst 9800-l | All versions |
CPE
Remediation
| |
| cisco catalyst 9800-l-c | All versions |
CPE
Remediation
| |
| cisco catalyst 9800-l-f | All versions |
CPE
Remediation
| |
| cisco catalyst 9800 embedded wireless controller | All versions |
CPE
Remediation
| |
Change History
7 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Oct 30, 2025 | Modified Analysis | [email protected] |
| Nov 21, 2024 | CVE Modified | CVE |
| May 14, 2024 | CVE Modified | [email protected] |
| Nov 7, 2023 | CVE Modified | [email protected] |
| Oct 13, 2021 | Initial Analysis | [email protected] |