Memory leak in Cisco IOS XR - CVE-2021-1313

 

Memory leak in Cisco IOS XR - CVE-2021-1313

Published: February 3, 2021


Vulnerability identifier: #VU50304
CSH Severity: Medium
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Green
CVE-ID: CVE-2021-1313
CWE-ID: CWE-401
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vulnerable software:
Cisco IOS XR
Software vendor:
Cisco Systems, Inc

Description

The vulnerability allows a remote attacker to perform DoS attack on the target system.

The vulnerability exists due memory leak in the ingress packet processing function of Cisco IOS XR Software when processing ICMP or Telnet protocol packets. A remote attacker can send specially crafted packets to the affected system, trigger memory leak within the ENF_BROKER process and perform a denial of service (DoS) attack.


Remediation

Install updates from vendor's website.

External links