NULL pointer dereference in Cisco Systems, Inc products - CVE-2021-34737
Published: September 9, 2021
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to a NULL pointer dereference error in the DHCP version 4 (DHCPv4) server feature of Cisco IOS XR Software. A remote non-authenticated attacker can send specially crafted DHCPv4 messages to the affected device, trigger a NULL pointer dereference error and crash the dhcpd process.
Affected software
Cisco IOS XRv 9000 Router
Cisco ASR 9000 Series Aggregation Services Routers
NCS5500
NCS560
NCS540
Cisco IOS XR
How to mitigate CVE-2021-34737
Cisco ASR 9000 Series Aggregation Services Routers - addressed in versions 7.3.2, 7.4.1