CVE-2021-1588: Cisco NX-OS Software MPLS OAM Denial of Service Vulnerability
A vulnerability in the MPLS Operation, Administration, and Maintenance (OAM) feature of Cisco NX-OS Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper input validation when an affected device is processing an MPLS echo-request or echo-reply packet. An attacker could exploit this vulnerability by sending malicious MPLS echo-request or echo-reply packets to an interface that is enabled for MPLS forwarding on the affected device. A successful exploit could allow the attacker to cause the MPLS OAM process to crash and restart multiple times, causing the affected device to reload and resulting in a DoS condition.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2021-1588?
CVE-2021-1588 has a high severity rating as it can allow unauthenticated remote attackers to cause a denial of service condition.
How do I fix CVE-2021-1588?
To fix CVE-2021-1588, upgrade to a Cisco NX-OS version that is not affected by the vulnerability, as outlined in Cisco's security advisory.
Which Cisco NX-OS versions are affected by CVE-2021-1588?
CVE-2021-1588 affects Cisco NX-OS 7.0(3)i7(9), 8.4(1), and 9.3(7).
Can CVE-2021-1588 be exploited locally?
No, CVE-2021-1588 can only be exploited remotely by unauthenticated attackers.
What is the potential impact of CVE-2021-1588?
The potential impact of CVE-2021-1588 is a denial of service, which may render affected devices unreachable.