CVE-2021-1373: Cisco IOS XE Wireless Controller Software for the Catalyst 9000 Family CAPWAP Denial of Service Vulnerability
A vulnerability in the Control and Provisioning of Wireless Access Points (CAPWAP) protocol processing of Cisco IOS XE Wireless Controller Software for the Cisco Catalyst 9000 Family Wireless Controllers could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition of an affected device. The vulnerability is due to insufficient validation of CAPWAP packets. An attacker could exploit this vulnerability by sending a malformed CAPWAP packet to an affected device. A successful exploit could allow the attacker to cause the affected device to crash and reload, resulting in a DoS condition.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-1373?
CVE-2021-1373 is a vulnerability in the Control and Provisioning of Wireless Access Points (CAPWAP) protocol processing of Cisco IOS XE Wireless Controller Software for the Cisco Catalyst 9000 Family Wireless Controllers.
What is the severity of CVE-2021-1373?
CVE-2021-1373 has a severity value of 8.6, which is considered high.
How does CVE-2021-1373 affect Cisco IOS XE versions?
CVE-2021-1373 affects Cisco IOS XE versions 16.10.1, 16.10.1e, 16.10.1s, 16.11.1, 16.11.1a, 16.11.1b, 16.11.1c, 16.11.2, 16.12.1, 16.12.1s, 16.12.1t, 16.12.2s, 16.12.2t, 16.12.3, 16.12.3s, 16.12.4, 16.12.4a, 17.1.1, 17.1.1s, 17.1.1t, 17.1.2, 17.2.1, 17.2.1a, 17.2.3, and 17.3.1.
What is the impact of CVE-2021-1373?
CVE-2021-1373 could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on the affected Cisco Catalyst 9000 Family Wireless Controllers.
How can I fix CVE-2021-1373?
To fix CVE-2021-1373, it is recommended to upgrade to a fixed software release based on the Cisco IOS XE release train.