Improper Check for Unusual or Exceptional Conditions in Cisco Systems, Inc products - CVE-2021-1446
Published: March 29, 2021
Vulnerability identifier: #VU51769
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-1446
CWE-ID: CWE-754
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to a logic error that occurs when an affected device inspects certain DNS packets. A remote attacker can send specially crafted DNS packets and cause denial of service condition.
Affected software
Cisco ASR 1000 Series Aggregation Services Routers
Cloud Services Router 1000V Series
4000 Series Integrated Services Routers
Cisco 1000 Series Integrated Services Routers
Stratix 5800
Cisco IOS XE
Cloud Services Router 1000V Series
4000 Series Integrated Services Routers
Cisco 1000 Series Integrated Services Routers
Stratix 5800
Cisco IOS XE
How to mitigate CVE-2021-1446
Install update from vendor's website.
Cisco IOS XE - addressed in versions 16.6.8.15, 16.6.9, 16.9.6.7, 16.9.7, 16.12.5, 17.1.3, 17.3.1.62, 17.3.2, 17.3.2a, 17.4.0.137, 17.4.1, 17.5.0.25
Stratix 5800 - update to 16.12.01
Stratix 5800 - update to 16.12.01