#VU51736 Resource management error in Cisco Network Convergence System 5000 Series and Cisco IOS XE - CVE-2021-1394
Published: March 26, 2021
Vulnerability identifier: #VU51736
Vulnerability risk: Medium
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:U/U:Green
CVE-ID: CVE-2021-1394
CWE-ID: CWE-399
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerable software:
Cisco Network Convergence System 5000 Series
Cisco IOS XE
Cisco Network Convergence System 5000 Series
Cisco IOS XE
Software vendor:
Cisco Systems, Inc
Cisco Systems, Inc
Description
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to improper management of internal resources within the ingress traffic manager of Cisco IOS XE Software for Cisco Network Convergence System (NCS) 520 Routers when pressing IPv4 TCP traffic. A remote attacker can send a large number of crafted TCP packets to the affected device and perform a denial of service (DoS) attack.
Remediation
Install updates from vendor's website.