PT-2021-1812 · Cisco · Cisco Elastic Services Controller

Published

2021-01-20

·

Updated

2021-01-29

·

CVE-2021-1312

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions: Cisco Elastic Services Controller (ESC) (affected versions not specified)
Description: The issue is related to inadequate provisioning of kernel parameters for the maximum number of TCP connections and SYN backlog in the system resource management of Cisco Elastic Services Controller (ESC). This could allow an unauthenticated, remote attacker to cause a denial of service (DoS) to the health monitor API on an affected device by sending a flood of crafted TCP packets. A successful exploit could block TCP listening ports used by the health monitor API. The vulnerability only affects customers who use the health monitor API.
Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Resource Exhaustion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2021-00567
CVE-2021-1312

Affected Products

Cisco Elastic Services Controller