CVE-2021-1244
Last modified
CVE-2021-1244 is a medium-severity vulnerability rated 6.7/10 on the CVSS scale. Multiple vulnerabilities in Cisco Network Convergence System (NCS) 540 Series Routers, only when running Cisco IOS XR NCS540L software images, and Cisco IOS XR Software for the Cisco 8000 Series Routers could allow an authenticated, local attacker to execute unsigned code during the boot process on an affected device. For more information about these vulnerabilities, see the Details section of this advisory.. EPSS estimates a 0.20% chance of exploitation in the next 30 days.
Description
Multiple vulnerabilities in Cisco Network Convergence System (NCS) 540 Series Routers, only when running Cisco IOS XR NCS540L software images, and Cisco IOS XR Software for the Cisco 8000 Series Routers could allow an authenticated, local attacker to execute unsigned code during the boot process on an affected device. For more information about these vulnerabilities, see the Details section of this advisory.
Metrics
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Cisco | Ios Xr | < 7.0.12 |
| Cisco | Ios Xr | >= 7.1.0, < 7.2.1 |
| Cisco | Ios Xr | < 7.2.1 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2021-1244?
How severe is CVE-2021-1244?
How do I fix CVE-2021-1244?
How Strix Helps
- Same Subject, Wrong User: A Cross-Issuer Account Takeover in n8nStrix found an identity-binding bug in n8n's token-exchange flow enabling account takeover.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2021
- CVE-2021-1238Multiple vulnerabilities in the web-based management interfa…4.8
- CVE-2021-1239Multiple vulnerabilities in the web-based management interfa…4.8
- CVE-2021-1240A vulnerability in the loading process of specific DLLs in C…7.3
- CVE-2021-1241Multiple vulnerabilities in Cisco SD-WAN products could allo…7.5
- CVE-2021-1242A vulnerability in Cisco Webex Teams could allow an unauthen…4.3
- CVE-2021-1243A vulnerability in the Local Packet Transport Services (LPTS…7.5
- CVE-2021-1245Cisco Finesse and Cisco Unified CVP OpenSocial Gadget Editor…6.1
- CVE-2021-1246Cisco Finesse, Cisco Virtualized Voice Browser, and Cisco Un…6.1
- CVE-2021-1247Multiple vulnerabilities in certain REST API endpoints of Ci…8.8
- CVE-2021-1248Multiple vulnerabilities in certain REST API endpoints of Ci…7.2
- CVE-2021-1249Multiple vulnerabilities in the web-based management interfa…5.4
- CVE-2021-1250Multiple vulnerabilities in the web-based management interfa…5.4
Are you affected by CVE-2021-1244?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
