PT-2021-2260 · Cisco · Cisco Asr 5000 Series

Published

2021-03-03

·

Updated

2024-11-18

·

CVE-2021-1424

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Name of the Vulnerable Software and Affected Versions: Cisco ASR 5000 Series Software (StarOS) (affected versions not specified)
Description: A vulnerability in the ipsecmgr process could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition. This issue is due to insufficient validation of incoming Internet Key Exchange Version 2 (IKEv2) packets. An attacker could exploit this by sending specifically malformed IKEv2 packets to an affected device, causing the ipsecmgr process to restart and disrupting ongoing IKE negotiations.
Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Buffer Overflow

Weakness Enumeration

Related Identifiers

BDU:2021-01246
CVE-2021-1424

Affected Products

Cisco Asr 5000 Series