Resource management error in Cisco Systems, Inc products - CVE-2021-1621
Published: September 24, 2021
Vulnerability identifier: #VU56848
CSH Severity: Low
CVSS v4: 7.1 [CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-1621
CWE-ID: CWE-399
Exploitation vector: Adjecent network
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to improper handling of certain Layer 2 frames. A remote attacker on the local network can pass specially crafted data to the application and perform a denial of service (DoS) attack.
Affected software
Cisco 1000 Series Integrated Services Routers
Cisco 4000 Series Integrated Services Routers
Cisco ASR 1000 Series Aggregation Services Routers
Cisco Cloud Services Router 1000V Series
Integrated Services Virtual Routers
Cisco IOS XE
Cisco 4000 Series Integrated Services Routers
Cisco ASR 1000 Series Aggregation Services Routers
Cisco Cloud Services Router 1000V Series
Integrated Services Virtual Routers
Cisco IOS XE
How to mitigate CVE-2021-1621
Install updates from vendor's website.
Cisco IOS XE - update to 17.3.1