Resource management error in Cisco Systems, Inc products - CVE-2021-1611

 

Resource management error in Cisco Systems, Inc products - CVE-2021-1611

Published: September 24, 2021


Vulnerability identifier: #VU56858
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-1611
CWE-ID: CWE-399
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to improper management of internal resources within the application in Ethernet over GRE (EoGRE) packet processing. A remote attacker can pass specially crafted data to the application and perform a denial of service (DoS) attack.


Affected software

Catalyst 9800 Embedded Wireless Controller
Cisco Catalyst 9800 Series Wireless Controllers
Embedded Wireless Controller on Catalyst Access Points
Catalyst 9800 Wireless Controllers for Cloud
Cisco IOS XE

How to mitigate CVE-2021-1611

Install updates from vendor's website.

Cisco IOS XE - update to 17.5.1

External References

Related Security Bulletins