« Volver al listado

CVE-2021-27854

Estado: ModificadaMedia (4.7)—

Layer 2 network filtering capabilities such as IPv6 RA guard can be bypassed using combinations of VLAN 0 headers, LLC/SNAP headers, and converting frames from Ethernet to Wifi and its reverse.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (2)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2021-27854",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2021-27854",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2025-05-21T15:06:23.882465Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "CHANGED",
          "version": "3.1",
          "baseScore": 4.7,
          "attackVector": "ADJACENT_NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N",
          "integrityImpact": "LOW",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 1.4,
        "exploitabilityScore": 2.8
      },
      {
        "type": "Secondary",
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "cvssData": {
          "scope": "CHANGED",
          "version": "3.1",
          "baseScore": 4.7,
          "attackVector": "ADJACENT_NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N",
          "integrityImpact": "LOW",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 1.4,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "cret@cert.org",
      "affectedData": [
        {
          "vendor": "IETF",
          "product": "P802.1Q",
          "versions": [
            {
              "status": "affected",
              "version": "D1.0",
              "versionType": "custom",
              "lessThanOrEqual": "D1.0"
            }
          ]
        },
        {
          "vendor": "IETF",
          "product": "draft-ietf-v6ops-ra-guard",
          "versions": [
            {
              "status": "affected",
              "version": "08",
              "versionType": "custom",
              "lessThanOrEqual": "08"
            }
          ]
        },
        {
          "vendor": "IEEE",
          "product": "802.2",
          "versions": [
            {
              "status": "affected",
              "version": "802.2h-1997",
              "versionType": "custom",
              "lessThanOrEqual": "802.2h-1997"
            }
          ]
        }
      ]
    }
  ],
  "published": "2022-09-27T19:15:09.240",
  "references": [
    {
      "url": "https://blog.champtar.fr/VLAN0_LLC_SNAP/",
      "source": "cret@cert.org"
    },
    {
      "url": "https://datatracker.ietf.org/doc/draft-ietf-v6ops-ra-guard/08/",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "cret@cert.org"
    },
    {
      "url": "https://kb.cert.org/vuls/id/855201",
      "source": "cret@cert.org"
    },
    {
      "url": "https://standards.ieee.org/ieee/802.1Q/10323/",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "cret@cert.org"
    },
    {
      "url": "https://standards.ieee.org/ieee/802.2/1048/",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "cret@cert.org"
    },
    {
      "url": "https://blog.champtar.fr/VLAN0_LLC_SNAP/",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://datatracker.ietf.org/doc/draft-ietf-v6ops-ra-guard/08/",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://kb.cert.org/vuls/id/855201",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://standards.ieee.org/ieee/802.1Q/10323/",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://standards.ieee.org/ieee/802.2/1048/",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://www.kb.cert.org/vuls/id/855201",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "cret@cert.org",
      "description": [
        {
          "lang": "en",
          "value": "CWE-290"
        }
      ]
    },
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-290"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Layer 2 network filtering capabilities such as IPv6 RA guard can be bypassed using combinations of VLAN 0 headers, LLC/SNAP headers, and converting frames from Ethernet to Wifi and its reverse."
    },
    {
      "lang": "es",
      "value": "Las capacidades de filtrado de red de capa 2, como la protección RA de IPv6, pueden omitirse usando combinaciones de encabezados VLAN 0, encabezados LLC/SNAP y convirtiendo tramas de Ethernet a Wifi y su inversa"
    }
  ],
  "lastModified": "2026-06-17T03:45:31.400",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:ieee:ieee_802.2:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D5B0DDC2-21C5-4682-9AA2-055BF7C722DA",
              "versionEndIncluding": "802.2h-1997"
            }
          ],
          "operator": "OR"
        }
      ]
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:ietf:p802.1q:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "94105D2E-950F-4290-8840-301FA908BC8C",
              "versionEndIncluding": "d1.0"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cret@cert.org"
}