PT-2021-4742 · Cisco · Cisco Ios Xe
Published
2021-09-22
·
Updated
2021-10-05
·
CVE-2021-34697
CVSS v3.1
8.6
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Cisco IOS XE Software (affected versions not specified)
Description
A vulnerability in the Protection Against Distributed Denial of Service Attacks feature could allow an unauthenticated, remote attacker to conduct denial of service (DoS) attacks to or through the affected device. This issue is due to incorrect programming of the half-opened connections limit, TCP SYN flood limit, or TCP SYN cookie features when the features are configured in vulnerable releases of Cisco IOS XE Software. An attacker could exploit this vulnerability by attempting to flood traffic to or through the affected device, potentially initiating a DoS attack.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
DoS
Improper Initialization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cisco Ios Xe