Medium severity4.7NVD Advisory· Published Sep 27, 2022· Updated Jun 17, 2026
CVE-2021-27853
CVE-2021-27853
Description
Layer 2 network filtering capabilities such as IPv6 RA guard or ARP inspection can be bypassed using combinations of VLAN 0 headers and LLC/SNAP headers.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
104cpe:2.3:a:cisco:ios_xe:17.3.3:*:*:*:*:*:*:*+ 4 more
- cpe:2.3:a:cisco:ios_xe:17.3.3:*:*:*:*:*:*:*
- cpe:2.3:o:cisco:ios_xe:15.2\(07\)e02:*:*:*:*:*:*:*
- cpe:2.3:o:cisco:ios_xe:15.2\(07\)e03:*:*:*:*:*:*:*
- cpe:2.3:o:cisco:ios_xe:17.4.1:*:*:*:*:*:*:*
- cpe:2.3:o:cisco:ios_xe:17.6.1:*:*:*:*:*:*:*
- cpe:2.3:o:cisco:catalyst_6503-e_firmware:15.5\(01.01.85\)sy07:*:*:*:*:*:*:*
- cpe:2.3:o:cisco:catalyst_6504-e_firmware:15.5\(01.01.85\)sy07:*:*:*:*:*:*:*
- cpe:2.3:o:cisco:catalyst_6506-e_firmware:15.5\(01.01.85\)sy07:*:*:*:*:*:*:*
- cpe:2.3:o:cisco:catalyst_6509-e_firmware:15.5\(01.01.85\)sy07:*:*:*:*:*:*:*
- cpe:2.3:o:cisco:catalyst_6509-neb-a_firmware:15.5\(01.01.85\)sy07:*:*:*:*:*:*:*
- cpe:2.3:o:cisco:catalyst_6509-v-e_firmware:15.5\(01.01.85\)sy07:*:*:*:*:*:*:*
- cpe:2.3:o:cisco:catalyst_6513-e_firmware:15.5\(01.01.85\)sy07:*:*:*:*:*:*:*
- cpe:2.3:o:cisco:catalyst_6800ia_firmware:15.5\(01.01.85\)sy07:*:*:*:*:*:*:*
- cpe:2.3:o:cisco:catalyst_6807-xl_firmware:15.5\(01.01.85\)sy07:*:*:*:*:*:*:*
- cpe:2.3:o:cisco:catalyst_6840-x_firmware:15.5\(01.01.85\)sy07:*:*:*:*:*:*:*
- cpe:2.3:o:cisco:catalyst_6880-x_firmware:15.5\(01.01.85\)sy07:*:*:*:*:*:*:*
- cpe:2.3:o:cisco:catalyst_c6816-x-le_firmware:15.5\(01.01.85\)sy07:*:*:*:*:*:*:*
- cpe:2.3:o:cisco:catalyst_c6824-x-le-40g_firmware:15.5\(01.01.85\)sy07:*:*:*:*:*:*:*
- cpe:2.3:o:cisco:catalyst_c6832-x-le_firmware:15.5\(01.01.85\)sy07:*:*:*:*:*:*:*
- cpe:2.3:o:cisco:catalyst_c6840-x-le-40g_firmware:15.5\(01.01.85\)sy07:*:*:*:*:*:*:*
- cpe:2.3:o:cisco:meraki_ms210_firmware:-:*:*:*:*:*:*:*
- cpe:2.3:o:cisco:meraki_ms225_firmware:-:*:*:*:*:*:*:*
- cpe:2.3:o:cisco:meraki_ms250_firmware:-:*:*:*:*:*:*:*
- cpe:2.3:o:cisco:meraki_ms350_firmware:-:*:*:*:*:*:*:*
- cpe:2.3:o:cisco:meraki_ms355_firmware:-:*:*:*:*:*:*:*
- cpe:2.3:o:cisco:meraki_ms390_firmware:-:*:*:*:*:*:*:*
- cpe:2.3:o:cisco:meraki_ms410_firmware:-:*:*:*:*:*:*:*
- cpe:2.3:o:cisco:meraki_ms420_firmware:-:*:*:*:*:*:*:*
- cpe:2.3:o:cisco:meraki_ms425_firmware:-:*:*:*:*:*:*:*
- cpe:2.3:o:cisco:meraki_ms450_firmware:-:*:*:*:*:*:*:*
- cpe:2.3:o:cisco:n9k-c9316d-gx_firmware:9.3\(5\):*:*:*:*:*:*:*
- cpe:2.3:o:cisco:n9k-c9332d-gx2b_firmware:9.3\(5\):*:*:*:*:*:*:*
- cpe:2.3:o:cisco:n9k-c9348d-gx2a_firmware:9.3\(5\):*:*:*:*:*:*:*
- cpe:2.3:o:cisco:n9k-c93600cd-gx_firmware:9.3\(5\):*:*:*:*:*:*:*
- cpe:2.3:o:cisco:n9k-c9364d-gx2a_firmware:9.3\(5\):*:*:*:*:*:*:*
- cpe:2.3:o:cisco:n9k-x9432c-s_firmware:9.3\(5\):*:*:*:*:*:*:*
- cpe:2.3:o:cisco:n9k-x9464px_firmware:9.3\(5\):*:*:*:*:*:*:*
- cpe:2.3:o:cisco:n9k-x9464tx2_firmware:9.3\(5\):*:*:*:*:*:*:*
- cpe:2.3:o:cisco:n9k-x9564px_firmware:9.3\(5\):*:*:*:*:*:*:*
- cpe:2.3:o:cisco:n9k-x9564tx_firmware:9.3\(5\):*:*:*:*:*:*:*
- cpe:2.3:o:cisco:n9k-x9636c-r_firmware:9.3\(5\):*:*:*:*:*:*:*
- cpe:2.3:o:cisco:n9k-x9636c-rx_firmware:9.3\(5\):*:*:*:*:*:*:*
- cpe:2.3:o:cisco:n9k-x97160yc-ex_firmware:9.3\(5\):*:*:*:*:*:*:*
- cpe:2.3:o:cisco:n9k-x9732c-ex_firmware:9.3\(5\):*:*:*:*:*:*:*
- cpe:2.3:o:cisco:n9k-x9732c-fx_firmware:9.3\(5\):*:*:*:*:*:*:*
- cpe:2.3:o:cisco:n9k-x9736c-ex_firmware:9.3\(5\):*:*:*:*:*:*:*
- cpe:2.3:o:cisco:n9k-x9736c-fx_firmware:9.3\(5\):*:*:*:*:*:*:*
- cpe:2.3:o:cisco:n9k-x9788tc-fx_firmware:9.3\(5\):*:*:*:*:*:*:*
- cpe:2.3:o:cisco:nexus_92160yc-x_firmware:9.3\(5\):*:*:*:*:*:*:*
- cpe:2.3:o:cisco:nexus_92300yc_firmware:9.3\(5\):*:*:*:*:*:*:*
- cpe:2.3:o:cisco:nexus_92304qc_firmware:9.3\(5\):*:*:*:*:*:*:*
- cpe:2.3:o:cisco:nexus_92348gc-x_firmware:9.3\(5\):*:*:*:*:*:*:*
- cpe:2.3:o:cisco:nexus_9236c_firmware:9.3\(5\):*:*:*:*:*:*:*
- cpe:2.3:o:cisco:nexus_9272q_firmware:9.3\(5\):*:*:*:*:*:*:*
- cpe:2.3:o:cisco:nexus_93108tc-ex_firmware:9.3\(5\):*:*:*:*:*:*:*
- cpe:2.3:o:cisco:nexus_93108tc-fx3p_firmware:9.3\(5\):*:*:*:*:*:*:*
- cpe:2.3:o:cisco:nexus_93108tc-fx_firmware:9.3\(5\):*:*:*:*:*:*:*
- cpe:2.3:o:cisco:nexus_93120tx_firmware:9.3\(5\):*:*:*:*:*:*:*
- cpe:2.3:o:cisco:nexus_93180yc-ex_firmware:9.3\(5\):*:*:*:*:*:*:*
- cpe:2.3:o:cisco:nexus_93180yc-fx3_firmware:9.3\(5\):*:*:*:*:*:*:*
- cpe:2.3:o:cisco:nexus_93180yc-fx_firmware:9.3\(5\):*:*:*:*:*:*:*
- cpe:2.3:o:cisco:nexus_93216tc-fx2_firmware:9.3\(5\):*:*:*:*:*:*:*
- cpe:2.3:o:cisco:nexus_93240yc-fx2_firmware:9.3\(5\):*:*:*:*:*:*:*
- cpe:2.3:o:cisco:nexus_9332c_firmware:9.3\(5\):*:*:*:*:*:*:*
- cpe:2.3:o:cisco:nexus_93360yc-fx2_firmware:9.3\(5\):*:*:*:*:*:*:*
- cpe:2.3:o:cisco:nexus_9336c-fx2-e_firmware:9.3\(5\):*:*:*:*:*:*:*
- cpe:2.3:o:cisco:nexus_9336c-fx2_firmware:9.3\(5\):*:*:*:*:*:*:*
- cpe:2.3:o:cisco:nexus_9348gc-fxp_firmware:9.3\(5\):*:*:*:*:*:*:*
- cpe:2.3:o:cisco:nexus_9364c-gx_firmware:9.3\(5\):*:*:*:*:*:*:*
- cpe:2.3:o:cisco:nexus_9364c_firmware:9.3\(5\):*:*:*:*:*:*:*
- cpe:2.3:o:cisco:nexus_9432pq_firmware:9.3\(5\):*:*:*:*:*:*:*
- cpe:2.3:o:cisco:nexus_9504_firmware:9.3\(5\):*:*:*:*:*:*:*
- cpe:2.3:o:cisco:nexus_9508_firmware:9.3\(5\):*:*:*:*:*:*:*
- cpe:2.3:o:cisco:nexus_9516_firmware:9.3\(5\):*:*:*:*:*:*:*
- cpe:2.3:o:cisco:nexus_9536pq_firmware:9.3\(5\):*:*:*:*:*:*:*
- cpe:2.3:o:cisco:nexus_9636pq_firmware:9.3\(5\):*:*:*:*:*:*:*
- cpe:2.3:o:cisco:nexus_9716d-gx_firmware:9.3\(5\):*:*:*:*:*:*:*
- cpe:2.3:o:cisco:nexus_9736pq_firmware:9.3\(5\):*:*:*:*:*:*:*
- cpe:2.3:o:cisco:nexus_9800_firmware:9.3\(5\):*:*:*:*:*:*:*
- cpe:2.3:o:cisco:nexus_x9636q-r_firmware:9.3\(5\):*:*:*:*:*:*:*
- cpe:2.3:o:cisco:sf-500-24mp_firmware:3.0.0.61:*:*:*:*:*:*:*
- cpe:2.3:o:cisco:sf500-18p_firmware:3.0.0.61:*:*:*:*:*:*:*
cpe:2.3:o:cisco:sf500-24_firmware:3.0.0.61:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:o:cisco:sf500-24_firmware:3.0.0.61:*:*:*:*:*:*:*
- cpe:2.3:o:cisco:sf500-48_firmware:3.0.0.61:*:*:*:*:*:*:*
- cpe:2.3:o:cisco:sf500-24p_firmware:3.0.0.61:*:*:*:*:*:*:*
- cpe:2.3:o:cisco:sf500-48mp_firmware:3.0.0.61:*:*:*:*:*:*:*
- cpe:2.3:o:cisco:sg500-28_firmware:3.0.0.61:*:*:*:*:*:*:*
cpe:2.3:o:cisco:sg500-28mpp_firmware:3.0.0.61:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:o:cisco:sg500-28mpp_firmware:3.0.0.61:*:*:*:*:*:*:*
- cpe:2.3:o:cisco:sg500-52_firmware:3.0.0.61:*:*:*:*:*:*:*
- cpe:2.3:o:cisco:sg500-52mp_firmware:3.0.0.61:*:*:*:*:*:*:*
- cpe:2.3:o:cisco:sg500-28p_firmware:3.0.0.61:*:*:*:*:*:*:*
- cpe:2.3:o:cisco:sg500-52p_firmware:3.0.0.61:*:*:*:*:*:*:*
- cpe:2.3:o:cisco:sg500x-24_firmware:3.0.0.61:*:*:*:*:*:*:*
- cpe:2.3:o:cisco:sg500x-24mpp_firmware:3.0.0.61:*:*:*:*:*:*:*
cpe:2.3:o:cisco:sg500x-24p_firmware:3.0.0.61:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:o:cisco:sg500x-24p_firmware:3.0.0.61:*:*:*:*:*:*:*
- cpe:2.3:o:cisco:sg500x-48p_firmware:3.0.0.61:*:*:*:*:*:*:*
- cpe:2.3:o:cisco:sg500x-48_firmware:3.0.0.61:*:*:*:*:*:*:*
- cpe:2.3:o:cisco:sg500x-48mpp_firmware:3.0.0.61:*:*:*:*:*:*:*
- IEEE/802.2v5Range: 802.2h-1997
- IETF/draft-ietf-v6ops-ra-guardv5Range: 08
Patches
Vulnerability mechanics
References
7- blog.champtar.fr/VLAN0_LLC_SNAP/nvdExploitThird Party Advisory
- datatracker.ietf.org/doc/draft-ietf-v6ops-ra-guard/08/nvdTechnical DescriptionThird Party Advisory
- kb.cert.org/vuls/id/855201nvdThird Party AdvisoryUS Government Resource
- standards.ieee.org/ieee/802.1Q/10323/nvdVendor Advisory
- standards.ieee.org/ieee/802.2/1048/nvdVendor Advisory
- tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-VU855201-J3z8CKTXnvdThird Party Advisory
- www.kb.cert.org/vuls/id/855201nvd
News mentions
0No linked articles in our index yet.