Resource exhaustion in Cisco Systems, Inc products - CVE-2021-1460
Published: March 30, 2021
Vulnerability identifier: #VU51788
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-1460
CWE-ID: CWE-400
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to insufficient error handling during packet processing in the Cisco IOx Application Framework. A remote attacker can trigger resource exhaustion and perform a denial of service (DoS) attack.
Affected software
809 Industrial Integrated Services Routers
829 Industrial Integrated Services Routers
CGR 1000 Compute Module
IC3000 Industrial Compute Gateway
Cisco IOx
Cisco IOS
829 Industrial Integrated Services Routers
CGR 1000 Compute Module
IC3000 Industrial Compute Gateway
Cisco IOx
Cisco IOS
How to mitigate CVE-2021-1460
Install updates from vendor's website.
IC3000 Industrial Compute Gateway - update to 1.3.2
Cisco IOx - update to 1.12.0.3
Cisco IOS - update to 15.9.3 M3
Cisco IOx - update to 1.12.0.3
Cisco IOS - update to 15.9.3 M3