CVE-2021-1389
CVE-2021-1389 is a medium-severity vulnerability in Cisco Ios Xr with a CVSS 3.x base score of 5.8. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-284.
Key facts
- Severity: Medium (CVSS 3.x base score 5.8)
- CVSS v2: 6.4
- EPSS exploit prediction: 1% (68th percentile)
- Actively exploited: Not listed in CISA KEV
- Weakness: CWE-284
- Affected product: Cisco Ios Xr
- Published:
- Last modified:
Description
A vulnerability in the IPv6 traffic processing of Cisco IOS XR Software and Cisco NX-OS Software for certain Cisco devices could allow an unauthenticated, remote attacker to bypass an IPv6 access control list (ACL) that is configured for an interface of an affected device. The vulnerability is due to improper processing of IPv6 traffic that is sent through an affected device. An attacker could exploit this vulnerability by sending crafted IPv6 packets that traverse the affected device. A successful exploit could allow the attacker to access resources that would typically be protected by the interface ACL.
Frequently asked questions
- What is CVE-2021-1389?
- A vulnerability in the IPv6 traffic processing of Cisco IOS XR Software and Cisco NX-OS Software for certain Cisco devices could allow an unauthenticated, remote attacker to bypass an IPv6 access control list (ACL) that is configured for an interface of an affected device. The vulnerability is due to improper processing of IPv6 traffic that is sent through an affected device. An attacker could exploit this vulnerability by sending crafted IPv6 packets that traverse the affected device. A successful exploit could allow the attacker to access resources that would typically be protected by the interface ACL.
- How severe is CVE-2021-1389?
- CVE-2021-1389 has a CVSS 3.x base score of 5.8, rated medium severity. It is exploitable over network with low attack complexity, requires no privileges and no user interaction. Impact on confidentiality is none, integrity low, and availability none.
- Is CVE-2021-1389 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 1% (68th percentile), an estimate of the probability of exploitation in the next 30 days.
- What products are affected by CVE-2021-1389?
- CVE-2021-1389 primarily affects Cisco Ios Xr. In total, 4 product configurations (CPEs) are listed as vulnerable; see the affected-products list for the exact versions.
- How do I fix CVE-2021-1389?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround.
- When was CVE-2021-1389 published?
- CVE-2021-1389 was published on 2021-02-04 and last updated on 2026-06-17.
References
Affected products (4)
- cpe:2.3:o:cisco:ios_xr:*:*:*:*:*:*:*:*
- cpe:2.3:o:cisco:ios_xr:7.1.0:*:*:*:*:*:*:*
- cpe:2.3:o:cisco:ios_xr:7.2.0:*:*:*:*:*:*:*
- cpe:2.3:o:cisco:nx-os:-:*:*:*:*:*:*:*
More vulnerabilities in Cisco Ios Xr
- CVE-2026-20274 — Critical (CVSS 9.8): As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XR Software engineering…
- CVE-2020-3284 — Critical (CVSS 9.8): A vulnerability in the enhanced Preboot eXecution Environment (PXE) boot loader for Cisco IOS XR 64-bit Software could…
- CVE-2019-1710 — Critical (CVSS 9.8): A vulnerability in the sysadmin virtual machine (VM) on Cisco ASR 9000 Series Aggregation Services Routers running…
- CVE-2025-20363 — Critical (CVSS 9.0): A vulnerability in the web services of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software, Cisco Secure…
- CVE-2026-20280 — High (CVSS 8.8): As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XR Software…
- CVE-2026-20046 — High (CVSS 8.8): A vulnerability in task group assignment for a specific CLI command in Cisco IOS XR Software could allow an…
All CVEs affecting Cisco Ios Xr →
Other CWE-284 (Improper Access Control) vulnerabilities
- CVE-2026-83944 — Critical (CVSS 10.0): Improper access control in Azure Logic Apps allows an unauthorized attacker to elevate privileges over a network.
- CVE-2026-20192 — Critical (CVSS 10.0): As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Identity Services Engine…
- CVE-2026-87230 — Critical (CVSS 10.0): Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The…
- CVE-2026-54745 — Critical (CVSS 10.0): Kubeflow Pipelines enables users to build and deploy portable, scalable machine learning workflows. Prior to 2.17.0,…
- CVE-2026-18886 — Critical (CVSS 10.0): ServiceNow has remediated an improper access control vulnerability that was identified in the ServiceNow AI platform.…
- CVE-2026-76607 — Critical (CVSS 10.0): Joomla Extension - fabrikar.com - Missing ACL check in download element in Fabrik < 4.7.2.
Browse all CWE-284 (Improper Access Control) vulnerabilities →