Memory leak in Cisco IOS XR - CVE-2021-1313
Published: February 3, 2021
Vulnerability identifier: #VU50304
CSH Severity: Medium
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Green
CVE-ID: CVE-2021-1313
CWE-ID: CWE-401
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerable software:
Cisco IOS XR
Cisco IOS XR
Software vendor:
Cisco Systems, Inc
Cisco Systems, Inc
Description
The vulnerability allows a remote attacker to perform DoS attack on the target system.
The vulnerability exists due memory leak in the ingress packet processing function of Cisco IOS XR Software when processing ICMP or Telnet protocol packets. A remote attacker can send specially crafted packets to the affected system, trigger memory leak within the ENF_BROKER process and perform a denial of service (DoS) attack.
Remediation
Install updates from vendor's website.