HIGH · 7.4

CVE-2021-1439

A vulnerability in the multicast DNS (mDNS) gateway feature of Cisco Aironet Series Access Points Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) conditio...

Vulnerability Description

A vulnerability in the multicast DNS (mDNS) gateway feature of Cisco Aironet Series Access Points Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to insufficient input validation of incoming mDNS traffic. An attacker could exploit this vulnerability by sending a crafted mDNS packet to an affected device through a wireless network that is configured in FlexConnect local switching mode or through a wired network on a configured mDNS VLAN. A successful exploit could allow the attacker to cause the access point (AP) to reboot, resulting in a DoS condition.

CVSS Score

7.4

HIGH

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
Attack Vector
ADJACENT_NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
CHANGED
Confidentiality
NONE
Integrity
NONE
Availability
HIGH

Affected Products

VendorProductVersions
CiscoAironet Access Point Software-
Cisco1100 Integrated Services Router-
CiscoAironet 1540-
CiscoAironet 1560-
CiscoAironet 1800-
CiscoAironet 2800-
CiscoAironet 3800-
CiscoAironet 4800-
CiscoCatalyst 9100-
CiscoCatalyst Iw6300-
CiscoEsw6300-
CiscoCatalyst 9800 Firmware>= 17.1, < 17.3.3
CiscoCatalyst 9800-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2021-1439?

CVE-2021-1439 is a vulnerability with a CVSS score of 7.4 (HIGH). A vulnerability in the multicast DNS (mDNS) gateway feature of Cisco Aironet Series Access Points Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) conditio...

How severe is CVE-2021-1439?

CVE-2021-1439 has been rated HIGH with a CVSS base score of 7.4/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2021-1439?

Check the references section above for vendor advisories and patch information. Affected products include: Cisco Aironet Access Point Software, Cisco 1100 Integrated Services Router, Cisco Aironet 1540, Cisco Aironet 1560, Cisco Aironet 1800.