Vulnerability Description
A vulnerability in the Layer 2 punt code of Cisco IOS XE Software could allow an unauthenticated, adjacent attacker to cause a queue wedge on an interface that receives specific Layer 2 frames, resulting in a denial of service (DoS) condition. This vulnerability is due to improper handling of certain Layer 2 frames. An attacker could exploit this vulnerability by sending specific Layer 2 frames on the segment the router is connected to. A successful exploit could allow the attacker to cause a queue wedge on the interface, resulting in a DoS condition.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Cisco | Ios Xe | < 17.3.1 |
| Cisco | 1000 Integrated Services Router | - |
| Cisco | 1100-4G\/6G Integrated Services Router | - |
| Cisco | 1100-4P Integrated Services Router | - |
| Cisco | 1100-8P Integrated Services Router | - |
| Cisco | 1100 Integrated Services Router | - |
| Cisco | 1101-4P Integrated Services Router | - |
| Cisco | 1101 Integrated Services Router | - |
| Cisco | 1109-2P Integrated Services Router | - |
| Cisco | 1109-4P Integrated Services Router | - |
| Cisco | 1109 Integrated Services Router | - |
| Cisco | 1111X-8P Integrated Services Router | - |
| Cisco | 1111X Integrated Services Router | - |
| Cisco | 111X Integrated Services Router | - |
| Cisco | 1120 Integrated Services Router | - |
| Cisco | 1160 Integrated Services Router | - |
| Cisco | 4000 Integrated Services Router | - |
| Cisco | 4221 Integrated Services Router | - |
| Cisco | 4321 Integrated Services Router | - |
| Cisco | 4331 Integrated Services Router | - |
Related Weaknesses (CWE)
References
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-qPatchVendor Advisory
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-qPatchVendor Advisory
FAQ
What is CVE-2021-1621?
CVE-2021-1621 is a vulnerability with a CVSS score of 7.4 (HIGH). A vulnerability in the Layer 2 punt code of Cisco IOS XE Software could allow an unauthenticated, adjacent attacker to cause a queue wedge on an interface that receives specific Layer 2 frames, result...
How severe is CVE-2021-1621?
CVE-2021-1621 has been rated HIGH with a CVSS base score of 7.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-1621?
Check the references section above for vendor advisories and patch information. Affected products include: Cisco Ios Xe, Cisco 1000 Integrated Services Router, Cisco 1100-4G\/6G Integrated Services Router, Cisco 1100-4P Integrated Services Router, Cisco 1100-8P Integrated Services Router.