Allocation of Resources Without Limits or Throttling in Cisco Systems, Inc products - CVE-2021-34735

 

Allocation of Resources Without Limits or Throttling in Cisco Systems, Inc products - CVE-2021-34735

Published: October 7, 2021


Vulnerability identifier: #VU57122
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-34735
CWE-ID: CWE-770
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to lack of proper rate limiting of ICMP packets on the Ethernet interface. A remote attacker can pass specially crafted data and cause a denial of service condition on the target system.


Affected software

ATA 190 Series Analog Telephone Adapters
ATA 192 Multiplatform Analog Telephone Adapter
ATA 191 Multiplatform Analog Telephone Adapter
ATA 191 Analog Telephone Adapter

How to mitigate CVE-2021-34735

Install updates from vendor's website.

ATA 192 Multiplatform Analog Telephone Adapter - update to 11.2.1
ATA 191 Multiplatform Analog Telephone Adapter - update to 11.2.1
ATA 191 Analog Telephone Adapter - update to 12.0(1)SR4

External References

Related Security Bulletins