#VU51736 Resource management error in Cisco Network Convergence System 5000 Series and Cisco IOS XE


Published: 2021-03-26

Vulnerability identifier: #VU51736

Vulnerability risk: Medium

CVSSv3.1: 4.6 [CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L/E:U/RL:O/RC:C]

CVE-ID: CVE-2021-1394

CWE-ID: CWE-399

Exploitation vector: Network

Exploit availability: No

Vulnerable software:
Cisco Network Convergence System 5000 Series
Hardware solutions / Routers & switches, VoIP, GSM, etc
Cisco IOS XE
Operating systems & Components / Operating system

Vendor: Cisco Systems, Inc

Description

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to improper management of internal resources within the ingress traffic manager of Cisco IOS XE Software for Cisco Network Convergence System (NCS) 520 Routers when pressing IPv4 TCP traffic. A remote attacker can send a large number of crafted TCP packets to the affected device and perform a denial of service (DoS) attack.

Mitigation
Install updates from vendor's website.

Vulnerable software versions

Cisco Network Convergence System 5000 Series: All versions

Cisco IOS XE: 16.10.1


External links
http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ncs520-tcp-ZpzzOxB
http://bst.cloudapps.cisco.com/bugsearch/bug/CSCvm96192


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.


Latest bulletins with this vulnerability