#VU51736 Resource management error in Cisco Network Convergence System 5000 Series and Cisco IOS XE - CVE-2021-1394 

 

#VU51736 Resource management error in Cisco Network Convergence System 5000 Series and Cisco IOS XE - CVE-2021-1394

Published: March 26, 2021


Vulnerability identifier: #VU51736
Vulnerability risk: Medium
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:U/U:Green
CVE-ID: CVE-2021-1394
CWE-ID: CWE-399
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vulnerable software:
Cisco Network Convergence System 5000 Series
Cisco IOS XE
Software vendor:
Cisco Systems, Inc

Description

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to improper management of internal resources within the ingress traffic manager of Cisco IOS XE Software for Cisco Network Convergence System (NCS) 520 Routers when pressing IPv4 TCP traffic. A remote attacker can send a large number of crafted TCP packets to the affected device and perform a denial of service (DoS) attack.


Remediation

Install updates from vendor's website.

External links