CVE-2021-1431: Cisco IOS XE SD-WAN Software vDaemon Denial of Service Vulnerability
A vulnerability in the vDaemon process of Cisco IOS XE SD-WAN Software could allow an unauthenticated, remote attacker to cause a device to reload, resulting a denial of service (DoS) condition. This vulnerability is due to insufficient handling of malformed packets. An attacker could exploit this vulnerability by sending crafted traffic to an affected device. A successful exploit could allow the attacker to cause the device to reload, resulting in a DoS condition.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-1431?
CVE-2021-1431 has a CVSS score that indicates a high severity, potentially leading to a denial of service condition.
How do I fix CVE-2021-1431?
To fix CVE-2021-1431, upgrade to a patched version of Cisco IOS XE recommended in the Cisco security advisory.
What systems are affected by CVE-2021-1431?
CVE-2021-1431 affects various versions of Cisco IOS XE including 3.15.1xbs, 16.11.1, and multiple versions up to 17.2.3.
What type of attack does CVE-2021-1431 facilitate?
CVE-2021-1431 allows an unauthenticated remote attacker to send malformed packets leading to a device reload, causing a denial of service.
Is CVE-2021-1431 easy to exploit?
Yes, exploitability of CVE-2021-1431 is considered high since it does not require authentication or local access.