HIGH✓ PATCH🇵🇱 Wersja polska

CVE-2021-34720

CVSS 8.6v3.1pub. 2021-09-09upd. 2024-11-21

A vulnerability in the IP Service Level Agreements (IP SLA) responder and Two-Way Active Measurement Protocol (TWAMP) features of Cisco IOS XR Software could allow an unauthenticated, remote attacker to cause device packet memory to become exhausted or cause the IP SLA process to crash, resulting in a denial of service (DoS) condition. This vulnerability exists because socket creation failures are mishandled during the IP SLA and TWAMP processes. An attacker could exploit this vulnerability by sending specific IP SLA or TWAMP packets to an affected device. A successful exploit could allow the attacker to exhaust the packet memory, which will impact other processes, such as routing protocols, or crash the IP SLA process.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
  • Cisco 8101 32fh

    HW
    Cisco
    all versions
  • Cisco 8101 32h

    HW
    Cisco
    all versions
  • Cisco 8102 64h

    HW
    Cisco
    all versions
  • Cisco 8201

    HW
    Cisco
    all versions
  • Cisco 8201 32fh

    HW
    Cisco
    all versions
  • Cisco 8202

    HW
    Cisco
    all versions
  • Cisco 8804

    HW
    Cisco
    all versions
  • Cisco 8808

    HW
    Cisco
    all versions
  • Cisco 8812

    HW
    Cisco
    all versions
  • Cisco 8818

    HW
    Cisco
    all versions
  • Cisco Asr 9000v V2

    HW
    Cisco
    all versions
  • Cisco Asr 9001

    HW
    Cisco
    all versions
  • Cisco Asr 9006

    HW
    Cisco
    all versions
  • Cisco Asr 9010

    HW
    Cisco
    all versions
  • Cisco Asr 9901

    HW
    Cisco
    all versions
  • Cisco Asr 9902

    HW
    Cisco
    all versions
  • Cisco Asr 9903

    HW
    Cisco
    all versions
  • Cisco Asr 9904

    HW
    Cisco
    all versions
  • Cisco Asr 9906

    HW
    Cisco
    all versions
  • Cisco Asr 9910

    HW
    Cisco
    all versions
  • Cisco Asr 9912

    HW
    Cisco
    all versions
  • Cisco Asr 9922

    HW
    Cisco
    all versions
  • Cisco IOS XR

    OS
    Cisco
    6.3.0 – 6.3.2 (excl.)6.5.0 – 7.2.2 (excl.)< 6.2.3
  • Cisco IOS Xrv

    HW
    Cisco
    all versions
  • Cisco IOS Xrv 9000

    HW
    Cisco
    all versions
  • Cisco Ncs 1001

    HW
    Cisco
    all versions
  • Cisco Ncs 1002

    HW
    Cisco
    all versions
  • Cisco Ncs 1004

    HW
    Cisco
    all versions
  • Cisco Ncs 4009

    HW
    Cisco
    all versions
  • Cisco Ncs 4016

    HW
    Cisco
    all versions
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
Tags
DoS
CWE
References

Related vulnerabilities

CVE-2025-32433CRITICAL10.0⚠ KEVPL ✓same product

Erlang/OTP SSH — nieuwierzytelniony RCE (CVSS 10.0)

CVE-2017-12240CRITICAL9.8⚠ KEVPL ✓same product

Buffer overflow w DHCP relay Cisco IOS — RCE bez uwierzytelnienia

CVE-2025-20363CRITICAL9.0PL ✓same product

RCE w web services Cisco ASA, FTD, IOS, IOS XE, IOS XR przez HTTP

CVE-2020-3284CRITICAL9.8PL ✓same product

Cisco IOS XR: wykonanie niepodpisanego kodu podczas bootowania PXE

CVE-2019-1710CRITICAL9.8PL ✓same product

Nieautoryzowany dostęp do sysadmin VM na Cisco ASR 9000 z IOS XR 64-bit