PT-2021-4047 · Cisco · Cisco Ios Xr
Published
2021-09-08
·
Updated
2022-10-25
·
CVE-2021-34720
CVSS v3.1
8.6
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Cisco IOS XR Software (affected versions not specified)
Description
A vulnerability in the IP Service Level Agreements (IP SLA) responder and Two-Way Active Measurement Protocol (TWAMP) features could allow an unauthenticated, remote attacker to cause device packet memory to become exhausted or cause the IP SLA process to crash, resulting in a denial of service (DoS) condition. This issue exists because socket creation failures are mishandled during the IP SLA and TWAMP processes. An attacker could exploit this by sending specific IP SLA or TWAMP packets to an affected device, potentially impacting other processes like routing protocols or crashing the IP SLA process.
Recommendations
For Cisco IOS XR Software, update to a version that includes the fix for this issue, as software updates have been released to address this vulnerability.
At the moment, there is no information about specific versions that contain a fix for this vulnerability.
Fix
DoS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cisco Ios Xr