MEDIUM · 4.7

CVE-2021-27853

Layer 2 network filtering capabilities such as IPv6 RA guard or ARP inspection can be bypassed using combinations of VLAN 0 headers and LLC/SNAP headers.

Vulnerability Description

Layer 2 network filtering capabilities such as IPv6 RA guard or ARP inspection can be bypassed using combinations of VLAN 0 headers and LLC/SNAP headers.

CVSS Score

4.7

MEDIUM

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N
Attack Vector
ADJACENT_NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
CHANGED
Confidentiality
NONE
Integrity
LOW
Availability
NONE

Affected Products

VendorProductVersions
IeeeIeee 802.2<= 802.2h-1997
IetfP802.1Q<= d1.0
CiscoCatalyst 6503-E Firmware15.5\(01.01.85\)sy07
CiscoCatalyst 6503-E-
CiscoCatalyst 6504-E Firmware15.5\(01.01.85\)sy07
CiscoCatalyst 6504-E-
CiscoCatalyst 6506-E Firmware15.5\(01.01.85\)sy07
CiscoCatalyst 6506-E-
CiscoCatalyst 6509-E Firmware15.5\(01.01.85\)sy07
CiscoCatalyst 6509-E-
CiscoCatalyst 6509-Neb-A Firmware15.5\(01.01.85\)sy07
CiscoCatalyst 6509-Neb-A-
CiscoCatalyst 6509-V-E Firmware15.5\(01.01.85\)sy07
CiscoCatalyst 6509-V-E-
CiscoCatalyst 6513-E Firmware15.5\(01.01.85\)sy07
CiscoCatalyst 6513-E-
CiscoCatalyst 6807-Xl Firmware15.5\(01.01.85\)sy07
CiscoCatalyst 6807-Xl-
CiscoCatalyst 6840-X Firmware15.5\(01.01.85\)sy07
CiscoCatalyst 6840-X-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2021-27853?

CVE-2021-27853 is a vulnerability with a CVSS score of 4.7 (MEDIUM). Layer 2 network filtering capabilities such as IPv6 RA guard or ARP inspection can be bypassed using combinations of VLAN 0 headers and LLC/SNAP headers.

How severe is CVE-2021-27853?

CVE-2021-27853 has been rated MEDIUM with a CVSS base score of 4.7/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2021-27853?

Check the references section above for vendor advisories and patch information. Affected products include: Ieee Ieee 802.2, Ietf P802.1Q, Cisco Catalyst 6503-E Firmware, Cisco Catalyst 6503-E, Cisco Catalyst 6504-E Firmware.