CVE-2021-34705: Cisco IOS
Medium severity, CVSS 5.3. EPSS: 1% chance of exploitation in the next 30 days.
A vulnerability in the Voice Telephony Service Provider (VTSP) service of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to bypass configured destination patterns and dial arbitrary numbers. This vulnerability is due to insufficient validation of dial strings at Foreign Exchange Office (FXO) interfaces. An attacker could exploit this vulnerability by sending a malformed dial string to an affected device via either the ISDN protocol or SIP. A successful exploit could allow the attacker to conduct toll fraud, resulting in unexpected financial impact to affected customers.
Affected products
- Cisco IOS: version 12.3(7)xm only; version 12.3(7)xr only; version 12.3(7)xr1 only; version 12.3(7)xr2 only; version 12.3(7)xr3 only; version 12.3(7)xr4 only; …
- Cisco IOS XE: affected versions not specified; version 3.7.0bs only; version 3.7.0s only; version 3.7.0xas only; version 3.7.0xbs only; version 3.7.1as only; …
Published 2021-09-23. Last modified 2026-06-17.