A vulnerability in the multicast DNS (mDNS) gateway feature of Cisco Aironet Series Access Points Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to insufficient input validation of incoming mDNS traffic. An attacker could exploit this vulnerability by sending a crafted mDNS packet to an affected device through a wireless network that is configured in FlexConnect local switching mode or through a wired network on a configured mDNS VLAN. A successful exploit could allow the attacker to cause the access point (AP) to reboot, resulting in a DoS condition.
Project Subscriptions
| Vendors | Products |
|---|---|
|
Cisco
Subscribe
|
1100 Integrated Services Router
Subscribe
Aironet 1540
Subscribe
Aironet 1560
Subscribe
Aironet 1800
Subscribe
Aironet 2800
Subscribe
Aironet 3800
Subscribe
Aironet 4800
Subscribe
Aironet Access Point Software
Subscribe
Catalyst 9100
Subscribe
Catalyst 9800
Subscribe
Catalyst 9800 Firmware
Subscribe
Catalyst Iw6300
Subscribe
Esw6300
Subscribe
|
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-6906 | A vulnerability in the multicast DNS (mDNS) gateway feature of Cisco Aironet Series Access Points Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to insufficient input validation of incoming mDNS traffic. An attacker could exploit this vulnerability by sending a crafted mDNS packet to an affected device through a wireless network that is configured in FlexConnect local switching mode or through a wired network on a configured mDNS VLAN. A successful exploit could allow the attacker to cause the access point (AP) to reboot, resulting in a DoS condition. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Sat, 09 Nov 2024 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: cisco
Published:
Updated: 2024-11-08T23:35:37.324Z
Reserved: 2020-11-13T00:00:00
Link: CVE-2021-1439
Updated: 2024-08-03T16:11:17.298Z
Status : Modified
Published: 2021-03-24T20:15:14.977
Modified: 2024-11-21T05:44:22.010
Link: CVE-2021-1439
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD