Логотип exploitDog
bind:CVE-2021-1620
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2021-1620

Количество 3

Количество 3

nvd логотип

CVE-2021-1620

больше 4 лет назад

A vulnerability in the Internet Key Exchange Version 2 (IKEv2) support for the AutoReconnect feature of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, remote attacker to exhaust the free IP addresses from the assigned local pool. This vulnerability occurs because the code does not release the allocated IP address under certain failure conditions. An attacker could exploit this vulnerability by trying to connect to the device with a non-AnyConnect client. A successful exploit could allow the attacker to exhaust the IP addresses from the assigned local pool, which prevents users from logging in and leads to a denial of service (DoS) condition.

CVSS3: 7.7
EPSS: Низкий
github логотип

GHSA-hj64-pmxg-fcx3

больше 3 лет назад

A vulnerability in the Internet Key Exchange Version 2 (IKEv2) support for the AutoReconnect feature of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, remote attacker to exhaust the free IP addresses from the assigned local pool. This vulnerability occurs because the code does not release the allocated IP address under certain failure conditions. An attacker could exploit this vulnerability by trying to connect to the device with a non-AnyConnect client. A successful exploit could allow the attacker to exhaust the IP addresses from the assigned local pool, which prevents users from logging in and leads to a denial of service (DoS) condition.

CVSS3: 7.7
EPSS: Низкий
fstec логотип

BDU:2022-00042

больше 4 лет назад

Уязвимость функции AutoReconnect операционной системы Cisco IOS XE, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 7.7
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2021-1620

A vulnerability in the Internet Key Exchange Version 2 (IKEv2) support for the AutoReconnect feature of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, remote attacker to exhaust the free IP addresses from the assigned local pool. This vulnerability occurs because the code does not release the allocated IP address under certain failure conditions. An attacker could exploit this vulnerability by trying to connect to the device with a non-AnyConnect client. A successful exploit could allow the attacker to exhaust the IP addresses from the assigned local pool, which prevents users from logging in and leads to a denial of service (DoS) condition.

CVSS3: 7.7
0%
Низкий
больше 4 лет назад
github логотип
GHSA-hj64-pmxg-fcx3

A vulnerability in the Internet Key Exchange Version 2 (IKEv2) support for the AutoReconnect feature of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, remote attacker to exhaust the free IP addresses from the assigned local pool. This vulnerability occurs because the code does not release the allocated IP address under certain failure conditions. An attacker could exploit this vulnerability by trying to connect to the device with a non-AnyConnect client. A successful exploit could allow the attacker to exhaust the IP addresses from the assigned local pool, which prevents users from logging in and leads to a denial of service (DoS) condition.

CVSS3: 7.7
0%
Низкий
больше 3 лет назад
fstec логотип
BDU:2022-00042

Уязвимость функции AutoReconnect операционной системы Cisco IOS XE, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 7.7
0%
Низкий
больше 4 лет назад

Уязвимостей на страницу