CVE-2021-1288: Cisco IOS XR Software Enf Broker Denial of Service Vulnerability
Multiple vulnerabilities in the ingress packet processing function of Cisco IOS XR Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. For more information about these vulnerabilities, see the Details section of this advisory.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-1288?
CVE-2021-1288 is a vulnerability in the ingress packet processing function of Cisco IOS XR Software that allows an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device.
How does CVE-2021-1288 affect Cisco IOS XR Software?
CVE-2021-1288 affects Cisco IOS XR Software versions 5.0.0 to 5.2.6, 5.3.0 to 5.3.4, and 6.0.0 to 6.0.2.
What is the severity of CVE-2021-1288?
CVE-2021-1288 has a severity rating of 7.5 (high).
How can an attacker exploit CVE-2021-1288?
An unauthenticated, remote attacker can exploit CVE-2021-1288 by sending specially crafted packets to the affected device, causing it to enter a DoS condition.
Is there a fix for CVE-2021-1288?
Yes, Cisco has released software updates to address the vulnerability. Please refer to the Cisco Security Advisory for more information.