#VU51788 Resource exhaustion in Cisco Systems, Inc products - CVE-2021-1460
Published: March 30, 2021
Vulnerability identifier: #VU51788
Vulnerability risk: Medium
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:U/U:Green
CVE-ID: CVE-2021-1460
CWE-ID: CWE-400
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerable software:
809 Industrial Integrated Services Routers
829 Industrial Integrated Services Routers
CGR 1000 Compute Module
IC3000 Industrial Compute Gateway
Cisco IOx
Cisco IOS
809 Industrial Integrated Services Routers
829 Industrial Integrated Services Routers
CGR 1000 Compute Module
IC3000 Industrial Compute Gateway
Cisco IOx
Cisco IOS
Software vendor:
Cisco Systems, Inc
Cisco Systems, Inc
Description
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to insufficient error handling during packet processing in the Cisco IOx Application Framework. A remote attacker can trigger resource exhaustion and perform a denial of service (DoS) attack.
Remediation
Install updates from vendor's website.