CVE-2021-27862

Layer 2 network filtering capabilities such as IPv6 RA guard can be bypassed using LLC/SNAP headers with invalid length and Ethernet to Wifi frame conversion (and optionally VLAN0 headers).
Configurations

Configuration 1 (hide)

cpe:2.3:a:ieee:ieee_802.2:*:*:*:*:*:*:*:*

Configuration 2 (hide)

cpe:2.3:a:ietf:p802.1q:*:*:*:*:*:*:*:*

History

12 Oct 2022, 13:15

Type Values Removed Values Added
References
  • (MISC) https://kb.cert.org/vuls/id/855201 -
  • (MISC) https://blog.champtar.fr/VLAN0_LLC_SNAP/ -

03 Oct 2022, 17:42

Type Values Removed Values Added
CPE cpe:2.3:a:ietf:p802.1q:*:*:*:*:*:*:*:*
cpe:2.3:a:ieee:ieee_802.2:*:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 4.7
References (CONFIRM) https://standards.ieee.org/ieee/802.2/1048/ - (CONFIRM) https://standards.ieee.org/ieee/802.2/1048/ - Vendor Advisory
References (CONFIRM) https://datatracker.ietf.org/doc/draft-ietf-v6ops-ra-guard/08/ - (CONFIRM) https://datatracker.ietf.org/doc/draft-ietf-v6ops-ra-guard/08/ - Vendor Advisory
CWE CWE-290
First Time Ietf
Ieee
Ieee ieee 802.2
Ietf p802.1q

27 Sep 2022, 19:15

Type Values Removed Values Added
New CVE

Information

Published : 2022-09-27 19:15

Updated : 2023-12-10 14:35


NVD link : CVE-2021-27862

Mitre link : CVE-2021-27862

CVE.ORG link : CVE-2021-27862


JSON object : View

Products Affected

ieee

  • ieee_802.2

ietf

  • p802.1q
CWE
CWE-290

Authentication Bypass by Spoofing

CWE-130

Improper Handling of Length Parameter Inconsistency