Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2021-1622

Опубликовано: 23 сент. 2021
Источник: nvd
CVSS3: 8.6
CVSS2: 4.3
EPSS Низкий

Описание

A vulnerability in the Common Open Policy Service (COPS) of Cisco IOS XE Software for Cisco cBR-8 Converged Broadband Routers could allow an unauthenticated, remote attacker to cause resource exhaustion, resulting in a denial of service (DoS) condition. This vulnerability is due to a deadlock condition in the code when processing COPS packets under certain conditions. An attacker could exploit this vulnerability by sending COPS packets with high burst rates to an affected device. A successful exploit could allow the attacker to cause the CPU to consume excessive resources, which prevents other control plane processes from obtaining resources and results in a DoS.

Уязвимые конфигурации

Конфигурация 1

Одновременно

Одно из

cpe:2.3:o:cisco:ios_xe:*:*:*:*:*:*:*:*
Версия до 16.12.1z1 (исключая)
cpe:2.3:o:cisco:ios_xe:17.3.1x:*:*:*:*:*:*:*

Одно из

cpe:2.3:h:cisco:7600_router:-:*:*:*:*:*:*:*
cpe:2.3:h:cisco:asr_901-12c-f-d:-:*:*:*:*:*:*:*
cpe:2.3:h:cisco:asr_901-12c-ft-d:-:*:*:*:*:*:*:*
cpe:2.3:h:cisco:asr_901-4c-f-d:-:*:*:*:*:*:*:*
cpe:2.3:h:cisco:asr_901-4c-ft-d:-:*:*:*:*:*:*:*
cpe:2.3:h:cisco:asr_901-6cz-f-a:-:*:*:*:*:*:*:*
cpe:2.3:h:cisco:asr_901-6cz-f-d:-:*:*:*:*:*:*:*
cpe:2.3:h:cisco:asr_901-6cz-fs-a:-:*:*:*:*:*:*:*
cpe:2.3:h:cisco:asr_901-6cz-fs-d:-:*:*:*:*:*:*:*
cpe:2.3:h:cisco:asr_901-6cz-ft-a:-:*:*:*:*:*:*:*
cpe:2.3:h:cisco:asr_901-6cz-ft-d:-:*:*:*:*:*:*:*
cpe:2.3:h:cisco:cbr-8:-:*:*:*:*:*:*:*

EPSS

Процентиль: 50%
0.00266
Низкий

8.6 High

CVSS3

4.3 Medium

CVSS2

Дефекты

CWE-833
CWE-667

Связанные уязвимости

github
больше 3 лет назад

A vulnerability in the Common Open Policy Service (COPS) of Cisco IOS XE Software for Cisco cBR-8 Converged Broadband Routers could allow an unauthenticated, remote attacker to cause resource exhaustion, resulting in a denial of service (DoS) condition. This vulnerability is due to a deadlock condition in the code when processing COPS packets under certain conditions. An attacker could exploit this vulnerability by sending COPS packets with high burst rates to an affected device. A successful exploit could allow the attacker to cause the CPU to consume excessive resources, which prevents other control plane processes from obtaining resources and results in a DoS.

CVSS3: 8.6
fstec
больше 4 лет назад

Уязвимость ядра Common Open Policy Service (COPS) операционных систем Cisco IOS XE, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 50%
0.00266
Низкий

8.6 High

CVSS3

4.3 Medium

CVSS2

Дефекты

CWE-833
CWE-667