Resource management error in Cisco IOS XR - CVE-2021-1288

 

Resource management error in Cisco IOS XR - CVE-2021-1288

Published: February 3, 2021


Vulnerability identifier: #VU50303
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-1288
CWE-ID: CWE-399
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists in the ingress packet processing function of Cisco IOS XR Software when processing Telnet protocol packets. A remote attacker can send specially crafted Telnet packets to the affected system and crash the ENF_BROKER process.


Affected software

Cisco IOS XR

How to mitigate CVE-2021-1288

Install updates from vendor's website.

Cisco IOS XR - addressed in versions 5.1.3 .SMU, 5.2.6, 5.2.47, 5.3.2 .SMU, 5.3.3 .SMU, 5.3.4, 6.0.1, 6.0.2, 6.1.1, 6.1.2, 6.1.3, 6.1.4, 6.1.12, 6.1.21, 6.1.22, 6.1.31, 6.1.32, 6.1.33, 6.1.42, 6.1.45, 6.2.1, 6.2.2, 6.2.3, 6.2.25, 6.3.1, 6.3.2, 6.3.3, 6.3.15, 6.4.0, 6.4.1, 6.4.2, 6.5.1, 6.5.15, 6.5.90, 6.5.92, 6.5.93, 6.7.2, 7.0.1, 7.0.2, 7.2.1

External References

Related Security Bulletins