CVE-2021-1377: Cisco IOS and IOS XE Software ARP Resource Management Exhaustion Denial of Service Vulnerability
A vulnerability in Address Resolution Protocol (ARP) management of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to prevent an affected device from resolving ARP entries for legitimate hosts on the connected subnets. This vulnerability exists because ARP entries are mismanaged. An attacker could exploit this vulnerability by continuously sending traffic that results in incomplete ARP entries. A successful exploit could allow the attacker to cause ARP requests on the device to be unsuccessful for legitimate hosts, resulting in a denial of service (DoS) condition.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-1377?
The severity of CVE-2021-1377 is classified as high, allowing attackers to disrupt network operations.
How do I fix CVE-2021-1377?
To fix CVE-2021-1377, update your Cisco IOS or IOS XE devices to the latest version that addresses this vulnerability.
What types of devices are affected by CVE-2021-1377?
CVE-2021-1377 affects various Cisco IOS and IOS XE software versions as outlined in the advisory.
Is CVE-2021-1377 exploitable remotely?
Yes, CVE-2021-1377 can be exploited by unauthenticated, remote attackers.
What impact does CVE-2021-1377 have on network operations?
CVE-2021-1377 can prevent a device from resolving ARP entries for legitimate hosts, potentially leading to significant network disruptions.