HIGH · 7.4

CVE-2021-1621

A vulnerability in the Layer 2 punt code of Cisco IOS XE Software could allow an unauthenticated, adjacent attacker to cause a queue wedge on an interface that receives specific Layer 2 frames, result...

Vulnerability Description

A vulnerability in the Layer 2 punt code of Cisco IOS XE Software could allow an unauthenticated, adjacent attacker to cause a queue wedge on an interface that receives specific Layer 2 frames, resulting in a denial of service (DoS) condition. This vulnerability is due to improper handling of certain Layer 2 frames. An attacker could exploit this vulnerability by sending specific Layer 2 frames on the segment the router is connected to. A successful exploit could allow the attacker to cause a queue wedge on the interface, resulting in a DoS condition.

CVSS Score

7.4

HIGH

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
Attack Vector
ADJACENT_NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
CHANGED
Confidentiality
NONE
Integrity
NONE
Availability
HIGH

Affected Products

VendorProductVersions
CiscoIos Xe< 17.3.1
Cisco1000 Integrated Services Router-
Cisco1100-4G\/6G Integrated Services Router-
Cisco1100-4P Integrated Services Router-
Cisco1100-8P Integrated Services Router-
Cisco1100 Integrated Services Router-
Cisco1101-4P Integrated Services Router-
Cisco1101 Integrated Services Router-
Cisco1109-2P Integrated Services Router-
Cisco1109-4P Integrated Services Router-
Cisco1109 Integrated Services Router-
Cisco1111X-8P Integrated Services Router-
Cisco1111X Integrated Services Router-
Cisco111X Integrated Services Router-
Cisco1120 Integrated Services Router-
Cisco1160 Integrated Services Router-
Cisco4000 Integrated Services Router-
Cisco4221 Integrated Services Router-
Cisco4321 Integrated Services Router-
Cisco4331 Integrated Services Router-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2021-1621?

CVE-2021-1621 is a vulnerability with a CVSS score of 7.4 (HIGH). A vulnerability in the Layer 2 punt code of Cisco IOS XE Software could allow an unauthenticated, adjacent attacker to cause a queue wedge on an interface that receives specific Layer 2 frames, result...

How severe is CVE-2021-1621?

CVE-2021-1621 has been rated HIGH with a CVSS base score of 7.4/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2021-1621?

Check the references section above for vendor advisories and patch information. Affected products include: Cisco Ios Xe, Cisco 1000 Integrated Services Router, Cisco 1100-4G\/6G Integrated Services Router, Cisco 1100-4P Integrated Services Router, Cisco 1100-8P Integrated Services Router.