CVE-2021-1439: Cisco Aironet Access Points FlexConnect Multicast DNS Denial of Service Vulnerability
A vulnerability in the multicast DNS (mDNS) gateway feature of Cisco Aironet Series Access Points Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to insufficient input validation of incoming mDNS traffic. An attacker could exploit this vulnerability by sending a crafted mDNS packet to an affected device through a wireless network that is configured in FlexConnect local switching mode or through a wired network on a configured mDNS VLAN. A successful exploit could allow the attacker to cause the access point (AP) to reboot, resulting in a DoS condition.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2021-1439.
What is the severity of CVE-2021-1439?
The severity of CVE-2021-1439 is high with a score of 7.4.
What is the affected software for CVE-2021-1439?
The affected software for CVE-2021-1439 is Cisco Aironet Series Access Points Software.
What is the impact of CVE-2021-1439?
The impact of CVE-2021-1439 is a denial of service (DoS) condition on an affected device.
How can I fix CVE-2021-1439?
To fix CVE-2021-1439, it is recommended to apply the necessary updates or patches provided by Cisco.