Vulnerability identifier: #VU50303
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-1288
CWE-ID: CWE-399
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists in the ingress packet processing function of Cisco IOS XR Software when processing . A remote attacker can send specially crafted Telnet packets to the affected system and crash the ENF_BROKER process.
Affected software
Cisco IOS XR
How to mitigate CVE-2021-1288
Install updates from vendor's website.
Cisco IOS XR - addressed in versions 5.1.3 .SMU, 5.2.6, 5.2.47, 5.3.2 .SMU, 5.3.3 .SMU, 5.3.4, 6.0.1, 6.0.2, 6.1.1, 6.1.2, 6.1.3, 6.1.4, 6.1.12, 6.1.21, 6.1.22, 6.1.31, 6.1.32, 6.1.33, 6.1.42, 6.1.45, 6.2.1, 6.2.2, 6.2.3, 6.2.25, 6.3.1, 6.3.2, 6.3.3, 6.3.15, 6.4.0, 6.4.1, 6.4.2, 6.5.1, 6.5.15, 6.5.90, 6.5.92, 6.5.93, 6.7.2, 7.0.1, 7.0.2, 7.2.1
External References
Related Security Bulletins