← Vulnerability feed

Vulnerability record · CVE-2021-34727 · published 23 September 2021

CVE-2021-34727: Cisco ios xe sd-wan classic buffer overflow vulnerability

Cisco · Ios Xe Sd Wan

A vulnerability in the vDaemon process in Cisco IOS XE SD-WAN Software could allow an unauthenticated, remote attacker to cause a buffer overflow on an affected device. This vulnerability is due to insufficient bounds checking when an affected device processes traffic. An attacker could exploit this vulnerability by sending crafted traffic to the device. A successful exploit could allow the attacker to cause a buffer overflow and possibly execute arbitrary commands with root-level privileges, or cause the device to reload, which could result in a denial of service condition.

9.8 CVSS 3.1 Critical EPSS 2.6% · top 15.1% CWE-120 · Classic buffer overflow
9.8CVSS 3.1 base score, v2 10.0
2.6%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

A vulnerability in the vDaemon process in Cisco IOS XE SD-WAN Software could allow an unauthenticated, remote attacker to cause a buffer overflow on an affected device. This vulnerability is due to insufficient bounds checking when an affected device processes traffic. An attacker could exploit this vulnerability by sending crafted traffic to the device. A successful exploit could allow the attacker to cause a buffer overflow and possibly execute arbitrary commands with root-level privileges, or cause the device to reload, which could result in a denial of service condition.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2021-34727 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.7CVE-2025-20352Cisco IOS and IOS XE SNMP stack overflow allows DoS and root code executionA stack-based buffer overflow in the SNMP subsystem of Cisco IOS and IOS XE Software can be triggered by a crafted SNMP packet sent over IPv4 or IPv6…KEVEPSS 39%analysed9.8CVE-2021-1300Cisco ios xe sd-wan memory buffer overflow vulnerabilityMultiple vulnerabilities in Cisco SD-WAN products could allow an unauthenticated, remote attacker to execute attacks against an affected device. For …EPSS 2.1%9.8CVE-2021-1301Cisco ios xe sd-wan memory buffer overflow vulnerabilityMultiple vulnerabilities in Cisco SD-WAN products could allow an unauthenticated, remote attacker to execute attacks against an affected device. For …EPSS 2.1%9.8CVE-2020-3375Cisco sd-wan memory buffer overflow vulnerabilityA vulnerability in Cisco SD-WAN Solution Software could allow an unauthenticated, remote attacker to cause a buffer overflow on an affected device. T…EPSS 3.9%9.1CVE-2021-1619Cisco ios xe use of uninitialized resource vulnerabilityA vulnerability in the authentication, authorization, and accounting (AAA) function of Cisco IOS XE Software could allow an unauthenticated, remote a…EPSS 1.8%8.6CVE-2024-20455Cisco ios xe vulnerabilityA vulnerability in the process that classifies traffic that is going to the Unified Threat Defense (UTD) component of Cisco IOS XE Software in contro…EPSS 0.66%8.6CVE-2021-1279Cisco ios xe sd-wan memory buffer overflow vulnerabilityMultiple vulnerabilities in Cisco SD-WAN products could allow an unauthenticated, remote attacker to execute denial of service (DoS) attacks against …EPSS 1.4%8.6CVE-2021-1273Cisco ios xe sd-wan memory buffer overflow vulnerabilityMultiple vulnerabilities in Cisco SD-WAN products could allow an unauthenticated, remote attacker to execute denial of service (DoS) attacks against …EPSS 1.4%

Source: NIST National Vulnerability Database (record CVE-2021-34727), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.