PT-2021-5479 · Cisco · Cisco Ios Xe

Published

2021-09-22

·

Updated

2023-06-30

·

CVE-2021-1624

CVSS v3.1

8.6

High

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Cisco IOS XE Software (affected versions not specified)
Description The issue is related to the Rate Limiting Network Address Translation (NAT) feature of Cisco IOS XE Software, which could allow an unauthenticated, remote attacker to cause high CPU utilization in the Cisco QuantumFlow Processor of an affected device, resulting in a denial of service (DoS) condition. This is due to mishandling of the rate limiting feature within the QuantumFlow Processor. An attacker could exploit this by sending large amounts of traffic subject to NAT and rate limiting through an affected device, potentially causing the QuantumFlow Processor utilization to reach 100 percent.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

Resource Exhaustion

Weakness Enumeration

Related Identifiers

BDU:2021-06326
CVE-2021-1624

Affected Products

Cisco Ios Xe