Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2021-1136— Cisco IOS XR Software for Cisco 8000 Series Routers and Network Convergence System 540 Series Routers Image Verification Vulnerabilities

CVSS 6.7 · Medium EPSS 0.02% · P7
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2021-1136

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Cisco IOS XR Software for Cisco 8000 Series Routers and Network Convergence System 540 Series Routers Image Verification Vulnerabilities
Source: NVD (National Vulnerability Database)
Vulnerability Description
Multiple vulnerabilities in Cisco Network Convergence System (NCS) 540 Series Routers, only when running Cisco IOS XR NCS540L software images, and Cisco IOS XR Software for the Cisco 8000 Series Routers could allow an authenticated, local attacker to execute unsigned code during the boot process on an affected device. For more information about these vulnerabilities, see the Details section of this advisory.
Source: NVD (National Vulnerability Database)
CVSS Information
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Source: NVD (National Vulnerability Database)
Vulnerability Type
密码学签名的验证不恰当
Source: NVD (National Vulnerability Database)
Vulnerability Title
多款Cisco产品数据伪造问题漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Cisco 8000 Series Router和Cisco Network Convergence System 540 Series Routers都是美国Cisco公司的一款路由器设备。 多款 Cisco 路由器的 Cisco IOS XR 中存在数据伪造问题漏洞。该漏洞是由于受影响的设备上的GRUB引导加载程序版本未锁定引起的。攻击者可以通过从GRUB菜单修改引导过程来利用此漏洞。成功的利用可能使攻击者绕过信任启动链。以下产品及版本受到影响:Cisco 8000 Series Router,Cis
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
CiscoCisco IOS XR Software n/a -

II. Public POCs for CVE-2021-1136

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2021-1136

登录查看更多情报信息。

Same Patch Batch · Cisco · 2021-02-04 · 56 CVEs total

CVE-2021-12899.8 CRITICALCisco Small Business RV160, RV160W, RV260, RV260P, and RV260W VPN Routers Remote Code Exec
CVE-2021-12909.8 CRITICALCisco Small Business RV160, RV160W, RV260, RV260P, and RV260W VPN Routers Remote Code Exec
CVE-2021-12919.8 CRITICALCisco Small Business RV160, RV160W, RV260, RV260P, and RV260W VPN Routers Remote Code Exec
CVE-2021-12929.8 CRITICALCisco Small Business RV160, RV160W, RV260, RV260P, and RV260W VPN Routers Remote Code Exec
CVE-2021-12939.8 CRITICALCisco Small Business RV160, RV160W, RV260, RV260P, and RV260W VPN Routers Remote Code Exec
CVE-2021-12949.8 CRITICALCisco Small Business RV160, RV160W, RV260, RV260P, and RV260W VPN Routers Remote Code Exec
CVE-2021-12959.8 CRITICALCisco Small Business RV160, RV160W, RV260, RV260P, and RV260W VPN Routers Remote Code Exec
CVE-2021-13138.6 HIGHCisco IOS XR Software Enf Broker Denial of Service Vulnerability
CVE-2021-12888.6 HIGHCisco IOS XR Software Enf Broker Denial of Service Vulnerability
CVE-2021-12977.5 HIGHCisco Small Business RV160, RV160W, RV260, RV260P, and RV260W VPN Routers Arbitrary File W
CVE-2021-12967.5 HIGHCisco Small Business RV160, RV160W, RV260, RV260P, and RV260W VPN Routers Arbitrary File W
CVE-2021-12687.4 HIGHCisco IOS XR Software IPv6 Flood Denial of Service Vulnerability
CVE-2021-13227.2 HIGHCisco Small Business RV Series Routers Management Interface Remote Command Execution and D
CVE-2021-13307.2 HIGHCisco Small Business RV Series Routers Management Interface Remote Command Execution and D
CVE-2021-13237.2 HIGHCisco Small Business RV Series Routers Management Interface Remote Command Execution and D
CVE-2021-13247.2 HIGHCisco Small Business RV Series Routers Management Interface Remote Command Execution and D
CVE-2021-13257.2 HIGHCisco Small Business RV Series Routers Management Interface Remote Command Execution and D
CVE-2021-13297.2 HIGHCisco Small Business RV Series Routers Management Interface Remote Command Execution and D
CVE-2021-13277.2 HIGHCisco Small Business RV Series Routers Management Interface Remote Command Execution and D
CVE-2021-13267.2 HIGHCisco Small Business RV Series Routers Management Interface Remote Command Execution and D

Showing top 20 of 56 CVEs. View all on vendor page → →

IV. Related Vulnerabilities

V. Comments for CVE-2021-1136

No comments yet


Leave a comment