Resource exhaustion in Cisco Systems, Inc products - CVE-2021-1460

 

Resource exhaustion in Cisco Systems, Inc products - CVE-2021-1460

Published: March 30, 2021


Vulnerability identifier: #VU51788
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-1460
CWE-ID: CWE-400
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to insufficient error handling during packet processing in the Cisco IOx Application Framework. A remote attacker can trigger resource exhaustion and perform a denial of service (DoS) attack.


Affected software

809 Industrial Integrated Services Routers
829 Industrial Integrated Services Routers
CGR 1000 Compute Module
IC3000 Industrial Compute Gateway
Cisco IOx
Cisco IOS

How to mitigate CVE-2021-1460

Install updates from vendor's website.

IC3000 Industrial Compute Gateway - update to 1.3.2
Cisco IOx - update to 1.12.0.3
Cisco IOS - update to 15.9.3 M3

External References

Related Security Bulletins