Lucene search

K
cve[email protected]CVE-2021-1460
HistoryMar 24, 2021 - 8:15 p.m.

CVE-2021-1460

2021-03-2420:15:15
CWE-400
web.nvd.nist.gov
29
cisco
iox
application framework
vulnerability
denial of service
cve-2021-1460
cisco 809 industrial
cisco 829 industrial
cisco cgr 1000
cisco ic3000
dos

5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:N/A:P

7.5 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

0.002 Low

EPSS

Percentile

52.7%

A vulnerability in the Cisco IOx Application Framework of Cisco 809 Industrial Integrated Services Routers (Industrial ISRs), Cisco 829 Industrial ISRs, Cisco CGR 1000 Compute Module, and Cisco IC3000 Industrial Compute Gateway could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to insufficient error handling during packet processing. An attacker could exploit this vulnerability by sending a high and sustained rate of crafted TCP traffic to the IOx web server on an affected device. A successful exploit could allow the attacker to cause the IOx web server to stop processing requests, resulting in a DoS condition.

Affected configurations

NVD
Node
ciscoiosRange<15.9\(3\)m3
AND
cisco809_industrial_integrated_services_routerMatch-
OR
cisco829_industrial_integrated_services_routerMatch-
Node
ciscocgr1000_firmwareRange<1.12.0.3
AND
ciscocgr1000Match-
Node
ciscoic3000_industrial_compute_gateway_firmwareRange<1.3.2
AND
ciscoic3000_industrial_compute_gatewayMatch-
CPENameOperatorVersion
cisco:ioscisco ioslt15.9\(3\)m3

CNA Affected

[
  {
    "product": "Cisco IOS ",
    "vendor": "Cisco",
    "versions": [
      {
        "status": "affected",
        "version": "n/a"
      }
    ]
  }
]

5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:N/A:P

7.5 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

0.002 Low

EPSS

Percentile

52.7%

Related for CVE-2021-1460