CVE-2021-1424: Cisco ASR 5000 Series Software (StarOS) ipsecmgr Process Denial of Service Vulnerability
A vulnerability in the ipsecmgr process of Cisco ASR 5000 Series Software (StarOS) could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition. This vulnerability is due to insufficient validation of incoming Internet Key Exchange Version 2 (IKEv2) packets. An attacker could exploit this vulnerability by sending specifically malformed IKEv2 packets to an affected device. A successful exploit could allow the attacker to cause the ipsecmgr process to restart, which would disrupt ongoing IKE negotiations and result in a temporary DoS condition.Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-1424?
CVE-2021-1424 has been rated as high severity due to its potential to cause a denial of service condition.
How do I fix CVE-2021-1424?
To fix CVE-2021-1424, upgrade to a patched version of the Cisco ASR 5000 Series Software.
Who is affected by CVE-2021-1424?
CVE-2021-1424 affects users of the Cisco ASR 5000 Series Software.
What impact does CVE-2021-1424 have on Cisco ASR 5000 Series Software?
CVE-2021-1424 can be exploited by an unauthenticated remote attacker, leading to a denial of service condition.
Is there any workaround for CVE-2021-1424?
Currently, there are no documented workarounds for CVE-2021-1424; applying the fix is recommended.