First published: Thu Feb 04 2021(Updated: )
Multiple vulnerabilities in the ingress packet processing function of Cisco IOS XR Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. For more information about these vulnerabilities, see the Details section of this advisory.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco IOS XR | >=5.0.0<5.2.6 | |
Cisco IOS XR | >=5.3.0<5.3.4 | |
Cisco IOS XR | >=6.0.0<6.0.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-1288 is a vulnerability in the ingress packet processing function of Cisco IOS XR Software that allows an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device.
CVE-2021-1288 affects Cisco IOS XR Software versions 5.0.0 to 5.2.6, 5.3.0 to 5.3.4, and 6.0.0 to 6.0.2.
CVE-2021-1288 has a severity rating of 7.5 (high).
An unauthenticated, remote attacker can exploit CVE-2021-1288 by sending specially crafted packets to the affected device, causing it to enter a DoS condition.
Yes, Cisco has released software updates to address the vulnerability. Please refer to the Cisco Security Advisory for more information.