CVE-2021-1433
Last modified
CVE-2021-1433 is a high-severity vulnerability rated 8.1/10 on the CVSS scale. A vulnerability in the vDaemon process in Cisco IOS XE SD-WAN Software could allow an unauthenticated, remote attacker to cause a buffer overflow on an affected device. This vulnerability is due to insufficient bounds checking when the device processes traffic. EPSS estimates a 2.26% chance of exploitation in the next 30 days.
Description
A vulnerability in the vDaemon process in Cisco IOS XE SD-WAN Software could allow an unauthenticated, remote attacker to cause a buffer overflow on an affected device. This vulnerability is due to insufficient bounds checking when the device processes traffic. An attacker could exploit this vulnerability by sending crafted traffic to the device. The attacker must have a man-in-the-middle position between Cisco vManage and an associated device that is running an affected version of Cisco IOS XE SD-WAN Software. An exploit could allow the attacker to conduct a controllable buffer overflow attack (and possibly execute arbitrary commands as the root user) or cause a device reload, resulting in a denial of service (DoS) condition.
Metrics
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Cisco | Ios Xe | 3.15.1xbs |
| Cisco | Ios Xe | 3.15.2xbs |
| Cisco | Ios Xe | 16.12.1 |
| Cisco | Ios Xe | 16.12.1a |
| Cisco | Ios Xe | 16.12.1c |
| Cisco | Ios Xe | 16.12.1s |
| Cisco | Ios Xe | 16.12.1t |
| Cisco | Ios Xe | 16.12.1w |
| Cisco | Ios Xe | 16.12.1x |
| Cisco | Ios Xe | 16.12.1y |
| Cisco | Ios Xe | 16.12.1z |
| Cisco | Ios Xe | 16.12.1za |
| Cisco | Ios Xe | 16.12.2 |
| Cisco | Ios Xe | 16.12.2a |
| Cisco | Ios Xe | 16.12.2s |
| Cisco | Ios Xe | 16.12.2t |
| Cisco | Ios Xe | 16.12.3 |
| Cisco | Ios Xe | 16.12.3a |
| Cisco | Ios Xe | 16.12.3s |
| Cisco | Ios Xe | 17.2.1 |
| Cisco | Ios Xe | 17.2.1a |
| Cisco | Ios Xe | 17.2.1r |
| Cisco | Ios Xe | 17.2.1v |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2021-1433?
How severe is CVE-2021-1433?
How do I fix CVE-2021-1433?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2021
- CVE-2021-1427Multiple vulnerabilities in the install, uninstall, and upgr…7.8
- CVE-2021-1428Multiple vulnerabilities in the install, uninstall, and upgr…7.8
- CVE-2021-1429Multiple vulnerabilities in the install, uninstall, and upgr…7.8
- CVE-2021-1430Multiple vulnerabilities in the install, uninstall, and upgr…7.8
- CVE-2021-1431A vulnerability in the vDaemon process of Cisco IOS XE SD-WA…7.5
- CVE-2021-1432A vulnerability in the CLI of Cisco IOS XE SD-WAN Software c…7.3
- CVE-2021-1434A vulnerability in the CLI of Cisco IOS XE SD-WAN Software c…6
- CVE-2021-1435A vulnerability in the web UI of Cisco IOS XE Software could…7.2
- CVE-2021-1436A vulnerability in the CLI of Cisco IOS XE SD-WAN Software c…4.4
- CVE-2021-1437A vulnerability in the FlexConnect Upgrade feature of Cisco …7.5
- CVE-2021-1438A vulnerability in Cisco Wide Area Application Services (WAA…5.5
- CVE-2021-1439A vulnerability in the multicast DNS (mDNS) gateway feature …7.4
Are you affected by CVE-2021-1433?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
