CVE-2021-1352: Cisco IOS XE Software DECnet Phase IV/OSI Denial of Service Vulnerability
A vulnerability in the DECnet Phase IV and DECnet/OSI protocol processing of Cisco IOS XE Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to insufficient input validation of DECnet traffic that is received by an affected device. An attacker could exploit this vulnerability by sending DECnet traffic to an affected device. A successful exploit could allow the attacker to cause the affected device to reload, resulting in a DoS condition.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-1352?
CVE-2021-1352 has a high severity rating due to its potential to allow an unauthenticated attacker to cause a denial of service.
How do I fix CVE-2021-1352?
To fix CVE-2021-1352, upgrade your Cisco IOS XE Software to a version that is not affected by this vulnerability.
Which versions of Cisco IOS XE are affected by CVE-2021-1352?
CVE-2021-1352 affects multiple versions of Cisco IOS XE, including 16.4.1 through 17.3.1.
What impact does CVE-2021-1352 have on Cisco devices?
The impact of CVE-2021-1352 is a denial of service, which can render affected devices inoperable.
Are there workarounds for CVE-2021-1352?
There are no specific workarounds for CVE-2021-1352 aside from applying the recommended firmware update.