5.3

CVE-2021-1424

Cisco ASR 5000 Series Software (StarOS) ipsecmgr Process Denial of Service Vulnerability

A vulnerability in the ipsecmgr process of Cisco ASR 5000 Series Software (StarOS) could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition.
This vulnerability is due to insufficient validation of incoming Internet Key Exchange Version 2 (IKEv2) packets. An attacker could exploit this vulnerability by sending specifically malformed IKEv2 packets to an affected device. A successful exploit could allow the attacker to cause the ipsecmgr process to restart, which would disrupt ongoing IKE negotiations and result in a temporary DoS condition.Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.
Daten sind bereitgestellt durch das CVE Programm von Authorized Data Publishers (ADP) (Unstrukturiert)
Herstellercisco
Produkt asr_5000_series_software
Default Statusunknown
Version 21.15.7
Status affected
Version 21.13.10
Status affected
Version 21.14.1
Status affected
Version 21.11.5
Status affected
Version 21.13.8
Status affected
Version 21.14.5
Status affected
Version 21.12.8
Status affected
Version 21.13.11
Status affected
Version 21.11.8
Status affected
Version 21.12.9
Status affected
Version 21.15.5
Status affected
Version 21.11.7
Status affected
Version 21.13.5
Status affected
Version 21.12.0
Status affected
Version 21.15.2
Status affected
Version 21.11.6
Status affected
Version 21.14.2
Status affected
Version 21.12.3
Status affected
Version 21.15.0
Status affected
Version 21.11.2
Status affected
Version 21.13.7
Status affected
Version 21.12.4
Status affected
Version 21.12.12
Status affected
Version 21.13.4
Status affected
Version 21.12.5
Status affected
Version 21.14.a0
Status affected
Version 21.11.9
Status affected
Version 21.14.0
Status affected
Version 21.11.4
Status affected
Version 21.12.7
Status affected
Version 21.14.3
Status affected
Version 21.12.2
Status affected
Version 21.14.10
Status affected
Version 21.15.4
Status affected
Version 21.14.6
Status affected
Version 21.15.3
Status affected
Version 21.13.13
Status affected
Version 21.12.11
Status affected
Version 21.12.10
Status affected
Version 21.14.9
Status affected
Version 21.11.1
Status affected
Version 21.14.7
Status affected
Version 21.11.3
Status affected
Version 21.13.3
Status affected
Version 21.13.2
Status affected
Version 21.13.14
Status affected
Version 21.12.1
Status affected
Version 21.13.6
Status affected
Version 21.13.12
Status affected
Version 21.15.8
Status affected
Version 21.13.1
Status affected
Version 21.15.1
Status affected
Version 21.15.6
Status affected
Version 21.13.9
Status affected
Version 21.14.4
Status affected
Version 21.13.0
Status affected
Version 21.12.6
Status affected
Version 21.14.8
Status affected
Version 21.11.0
Status affected
Version 21.15.15
Status affected
Version 21.14.11
Status affected
Version 21.17.2
Status affected
Version 21.15.13
Status affected
Version 21.15.12
Status affected
Version 21.14.b15
Status affected
Version 21.17.0
Status affected
Version 21.15.10
Status affected
Version 21.13.16
Status affected
Version 21.14.12
Status affected
Version 21.15.20
Status affected
Version 21.11.10
Status affected
Version 21.15.18
Status affected
Version 21.15.14
Status affected
Version 21.13.15
Status affected
Version 21.15.21
Status affected
Version 21.15.17
Status affected
Version 21.17.1
Status affected
Version 21.14.b14
Status affected
Version 21.12.13
Status affected
Version 21.12.14
Status affected
Version 21.15.19
Status affected
Version 21.15.11
Status affected
Version 21.15.22
Status affected
Version 21.17.3
Status affected
Version 21.14.b13
Status affected
Version 21.15.16
Status affected
Version 21.14.b12
Status affected
Version 21.16.2
Status affected
Version 21.14.16
Status affected
Version 21.14.b17
Status affected
Version 21.15.24
Status affected
Version 21.16.c9
Status affected
Version 21.15.25
Status affected
Version 21.15.26
Status affected
Version 21.16.d0
Status affected
Version 21.17.4
Status affected
Version 21.15.27
Status affected
Version 21.13.17
Status affected
Version 21.18.0
Status affected
Version 21.15.28
Status affected
Version 21.14.17
Status affected
Version 21.16.d1
Status affected
Version 21.18.1
Status affected
Version 21.16.3
Status affected
Version 21.14.b18
Status affected
Version 21.16.c10
Status affected
Version 21.11.11
Status affected
Version 21.15.29
Status affected
Version 21.15.30
Status affected
Version 21.13.18
Status affected
Version 21.12.16
Status affected
Version 21.17.5
Status affected
Version 21.16.c11
Status affected
Version 21.15.32
Status affected
Version 21.13.19
Status affected
Version 21.15.33
Status affected
Version 21.11.12
Status affected
Version 21.19.0
Status affected
Version 21.18.2
Status affected
Version 21.14.19
Status affected
Version 21.19.1
Status affected
Version 21.17.6
Status affected
Version 21.11.13
Status affected
Version 21.12.17
Status affected
Version 21.15.36
Status affected
Version 21.18.3
Status affected
Version 21.14.b19
Status affected
Version 21.19.2
Status affected
Version 21.15.37
Status affected
Version 21.17.7
Status affected
Version 21.14.20
Status affected
Version 21.16.c12
Status affected
Version 21.18.4
Status affected
Version 21.19.3
Status affected
Version 21.13.20
Status affected
Version 21.15.40
Status affected
Version 21.14.b20
Status affected
Version 21.16.4
Status affected
Version 21.18.5
Status affected
Version 21.14.b21
Status affected
Version 21.16.c13
Status affected
Version 21.11.14
Status affected
Version 21.12.18
Status affected
Version 21.20.sv1
Status affected
Version 21.20.0
Status affected
Version 21.15.41
Status affected
Version 21.20.sv2
Status affected
Version 21.17.8
Status affected
Version 21.20.1
Status affected
Version 21.20.sv3
Status affected
Version 21.16.5
Status affected
Version 21.20.sv5
Status affected
Version 21.15.43
Status affected
Version 21.19.4
Status affected
Version 21.18.6
Status affected
Version 21.15.45
Status affected
Version 21.20.2
Status affected
Version 21.16.c14
Status affected
Version 21.17.9
Status affected
Version 21.11.15
Status affected
Version 21.14.22
Status affected
Version 21.20.3
Status affected
Version 21.15.46
Status affected
Version 21.18.7
Status affected
Version 21.19.n3
Status affected
Version 21.15.47
Status affected
Version 21.15.48
Status affected
Version 21.19.5
Status affected
Version 21.17.10
Status affected
Version 21.18.8
Status affected
Version 21.16.6
Status affected
Version 21.12.19
Status affected
Version 21.13.21
Status affected
Version 21.20.4
Status affected
Version 21.18.9
Status affected
Version 21.19.n4
Status affected
Version 21.17.11
Status affected
Version 21.18.11
Status affected
Version 21.19.6
Status affected
Version 21.16.c15
Status affected
Version 21.16.7
Status affected
Version 21.17.12
Status affected
Version 21.21.0
Status affected
Version 21.17.13
Status affected
Version 21.11.16
Status affected
Version 21.12.20
Status affected
Version 21.18.12
Status affected
Version 21.12.21
Status affected
Version 21.14.b22
Status affected
Version 21.19.7
Status affected
Version 21.20.6
Status affected
Version 21.18.13
Status affected
Version 21.19.n5
Status affected
Version 21.18.14
Status affected
Version 21.20.7
Status affected
Version 21.11.17
Status affected
Version 21.17.14
Status affected
Version 21.19.8
Status affected
Version 21.20.8
Status affected
Version 21.19.9
Status affected
Version 21.17.15
Status affected
Version 21.20.9
Status affected
Version 21.18.15
Status affected
Version 21.15.51
Status affected
Version 21.14.23
Status affected
Version 21.19.10
Status affected
Version 21.20.k6
Status affected
Version 21.11.18
Status affected
Version 21.19.n6
Status affected
Version 21.16.8
Status affected
Version 21.15.52
Status affected
Version 21.17.16
Status affected
Version 21.20.10
Status affected
Version 21.15.53
Status affected
Version 21.11.19
Status affected
Version 21.20.k7
Status affected
Version 21.15.54
Status affected
Version 21.20.11
Status affected
Version 21.20.u8
Status affected
Version 21.21.1
Status affected
Version 21.17.17
Status affected
Version 21.15.55
Status affected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.64% 0.701
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
psirt@cisco.com 5.3 3.9 1.4
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer

The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.