First published: Wed Sep 22 2021(Updated: )
A vulnerability in the Common Open Policy Service (COPS) of Cisco IOS XE Software for Cisco cBR-8 Converged Broadband Routers could allow an unauthenticated, remote attacker to cause resource exhaustion, resulting in a denial of service (DoS) condition. This vulnerability is due to a deadlock condition in the code when processing COPS packets under certain conditions. An attacker could exploit this vulnerability by sending COPS packets with high burst rates to an affected device. A successful exploit could allow the attacker to cause the CPU to consume excessive resources, which prevents other control plane processes from obtaining resources and results in a DoS. Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability. This advisory is available at the following link:https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cbr8-cops-Vc2ZsJSx This advisory is part of the September 2021 release of the Cisco IOS and IOS XE Software Security Advisory Bundled Publication. For a complete list of the advisories and links to them, see Cisco Event Response: September 2021 Semiannual Cisco IOS and IOS XE Software Security Advisory Bundled Publication.
Credit: This vulnerability was found during the resolution a Cisco TAC support case
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco cBR-8 Converged Broadband Routers |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of cisco-sa-cbr8-cops-Vc2ZsJSx is critical due to its potential to cause a denial of service.
To fix cisco-sa-cbr8-cops-Vc2ZsJSx, apply the latest security updates provided by Cisco for the IOS XE Software.
Cisco cBR-8 Converged Broadband Router users running vulnerable versions of IOS XE Software are affected by cisco-sa-cbr8-cops-Vc2ZsJSx.
cisco-sa-cbr8-cops-Vc2ZsJSx is caused by a vulnerability in the Common Open Policy Service (COPS) that can lead to resource exhaustion.
Yes, cisco-sa-cbr8-cops-Vc2ZsJSx can be exploited by unauthenticated remote attackers.