PT-2021-2503 · Cisco · Cisco Ios+1

Published

2021-03-24

·

Updated

2025-08-20

·

CVE-2021-1377

CVSS v3.1

5.8

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:L
Name of the Vulnerable Software and Affected Versions Cisco IOS Software and Cisco IOS XE Software (affected versions not specified)
Description A vulnerability in Address Resolution Protocol (ARP) management could allow an unauthenticated, remote attacker to prevent an affected device from resolving ARP entries for legitimate hosts on the connected subnets. This issue exists because ARP entries are mismanaged. An attacker could exploit this by continuously sending traffic that results in incomplete ARP entries, potentially causing a denial of service (DoS) condition.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2021-01879
CVE-2021-1377

Affected Products

Cisco Ios
Cisco Ios Xe