CVE-2021-1622: Cisco IOS XE Software for Cisco cBR-8 Converged Broadband Routers Common Open Policy Service Denial of Service Vulnerability
A vulnerability in the Common Open Policy Service (COPS) of Cisco IOS XE Software for Cisco cBR-8 Converged Broadband Routers could allow an unauthenticated, remote attacker to cause resource exhaustion, resulting in a denial of service (DoS) condition. This vulnerability is due to a deadlock condition in the code when processing COPS packets under certain conditions. An attacker could exploit this vulnerability by sending COPS packets with high burst rates to an affected device. A successful exploit could allow the attacker to cause the CPU to consume excessive resources, which prevents other control plane processes from obtaining resources and results in a DoS.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2021-1622?
CVE-2021-1622 is a vulnerability in the Common Open Policy Service (COPS) of Cisco IOS XE Software for Cisco cBR-8 Converged Broadband Routers.
What is the severity of CVE-2021-1622?
The severity of CVE-2021-1622 is high with a CVSS score of 8.6.
How does CVE-2021-1622 impact Cisco IOS XE Software?
CVE-2021-1622 could allow an unauthenticated, remote attacker to cause resource exhaustion, resulting in a denial of service (DoS) condition.
How can I fix CVE-2021-1622?
To mitigate the vulnerability, Cisco recommends upgrading to a fixed release of Cisco IOS XE Software.
Where can I find more information about CVE-2021-1622?
You can find more information about CVE-2021-1622 on the Cisco Security Advisory website.