Allocation of Resources Without Limits or Throttling in Cisco Systems, Inc products - CVE-2021-34735
Published: October 7, 2021
Vulnerability identifier: #VU57122
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-34735
CWE-ID: CWE-770
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to lack of proper rate limiting of ICMP packets on the Ethernet interface. A remote attacker can pass specially crafted data and cause a denial of service condition on the target system.
Affected software
ATA 190 Series Analog Telephone Adapters
ATA 192 Multiplatform Analog Telephone Adapter
ATA 191 Multiplatform Analog Telephone Adapter
ATA 191 Analog Telephone Adapter
ATA 192 Multiplatform Analog Telephone Adapter
ATA 191 Multiplatform Analog Telephone Adapter
ATA 191 Analog Telephone Adapter
How to mitigate CVE-2021-34735
Install updates from vendor's website.
ATA 192 Multiplatform Analog Telephone Adapter - update to 11.2.1
ATA 191 Multiplatform Analog Telephone Adapter - update to 11.2.1
ATA 191 Analog Telephone Adapter - update to 12.0(1)SR4
ATA 191 Multiplatform Analog Telephone Adapter - update to 11.2.1
ATA 191 Analog Telephone Adapter - update to 12.0(1)SR4