Security readout for executives and security teams
Plain-English summary
Some Cisco ASR 900 and ASR 920 routers may fail to enforce configured access control lists when those ACLs were configured outside the CLI. This can let unauthorized network traffic pass through controls the business expects to block.
Executive priority
Treat this as a moderate network-control risk. It may undermine segmentation or filtering assumptions on affected edge or aggregation routers, but available sources do not show active exploitation or broad product impact beyond Cisco ASR 900 and ASR 920 guidance.
Technical view
CVE-2021-34696 is an unauthenticated remote ACL bypass in Cisco IOS XE Software on ASR 900 and ASR 920 routers. The issue is incorrect hardware programming when ACLs are configured by non-CLI methods. Successful exploitation affects integrity of traffic filtering, not confidentiality or availability per CVSS.
Likely exposure
Exposure is most likely in organizations using Cisco ASR 900 or ASR 920 routers with ACLs provisioned through automation, management systems, or other non-CLI configuration paths. The source bundle does not provide affected version ranges.
Exploitation context
The CVE describes remote unauthenticated exploitation by sending traffic through an affected device. The source bundle marks CISA KEV as false and provides no cited evidence of active exploitation or public weaponization.
Researcher notes
The key technical condition is ACL programming via methods other than the configuration CLI, causing incorrect hardware programming. Sources do not include exact affected IOS XE versions, fixed releases, or workaround details in the bundle, so remediation should be tied to Cisco's advisory.
Mitigation direction
- Review Cisco's advisory for affected releases and fixed-software guidance.
- Inventory ASR 900 and ASR 920 routers running Cisco IOS XE Software.
- Identify ACLs configured through non-CLI management or automation paths.
- Prioritize remediation for routers enforcing boundary, tenant, or management-plane filtering.
- Check vendor guidance before relying on workaround assumptions.
Validation and detection
- Confirm whether deployed ASR 900 or ASR 920 models match Cisco's advisory scope.
- Review configuration management records for ACLs created outside the CLI.
- Verify ACL behavior after applying vendor-recommended remediation.
- Monitor for traffic unexpectedly allowed across protected router interfaces.
- Document affected devices with unknown IOS XE version status.
Public sources used
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
CWE-284: Authorization and privilege behavior lookup
Authorization weaknesses can support privilege escalation and valid-account review, depending on exploit path. Open the exact CWE lookup page first, then review the ATT&CK searches from that MITRE weakness context. This is a Glexia lookup hint, not an official ATT&CK mapping.
Open ATT&CK lookupCVE-2021-34696 mapping review
Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.
Open ATT&CK lookup- Severity
- Medium
- CVSS
- 5.8 (3.1)
- Known Exploited
- No
- Published
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N
CNA and ADP enrichment extracted from CVE v5
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
CVSS vector scores
1 official scoreWe collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N3.91.4Primary CVE scoreVulnerability scoring details
Base CVSS 3.1 score
5.8MediumVector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N
Source materials
- CVE List V5 sourceCVE List V5
- 20210922 Cisco ASR 900 and ASR 920 Series Aggregation Services Routers Access Control List Bypass VulnerabilityCVE reference · vendor-advisory, x_refsource_CISCO
Products and packages named in the record
CWE details
CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.
