Description
A vulnerability in the Rate Limiting Network Address Translation (NAT) feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause high CPU utilization in the Cisco QuantumFlow Processor of an affected device, resulting in a denial of service (DoS) condition. This vulnerability is due to mishandling of the rate limiting feature within the QuantumFlow Processor. An attacker could exploit this vulnerability by sending large amounts of traffic that would be subject to NAT and rate limiting through an affected device. A successful exploit could allow the attacker to cause the QuantumFlow Processor utilization to reach 100 percent on the affected device, resulting in a DoS condition.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-7091 | A vulnerability in the Rate Limiting Network Address Translation (NAT) feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause high CPU utilization in the Cisco QuantumFlow Processor of an affected device, resulting in a denial of service (DoS) condition. This vulnerability is due to mishandling of the rate limiting feature within the QuantumFlow Processor. An attacker could exploit this vulnerability by sending large amounts of traffic that would be subject to NAT and rate limiting through an affected device. A successful exploit could allow the attacker to cause the QuantumFlow Processor utilization to reach 100 percent on the affected device, resulting in a DoS condition. |
References
History
Thu, 07 Nov 2024 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Subscriptions
Cisco
Subscribe
Asr 1000
Subscribe
Asr 1000-esp100
Subscribe
Asr 1000-x
Subscribe
Asr 1001
Subscribe
Asr 1001-hx
Subscribe
Asr 1001-hx R
Subscribe
Asr 1001-x
Subscribe
Asr 1001-x R
Subscribe
Asr 1002
Subscribe
Asr 1002-hx
Subscribe
Asr 1002-hx R
Subscribe
Asr 1002-x
Subscribe
Asr 1002-x R
Subscribe
Asr 1004
Subscribe
Asr 1006
Subscribe
Asr 1006-x
Subscribe
Asr 1009-x
Subscribe
Asr 1013
Subscribe
Asr 1023
Subscribe
Ios Xe
Subscribe
Status: PUBLISHED
Assigner: cisco
Published:
Updated: 2024-11-07T21:59:45.997Z
Reserved: 2020-11-13T00:00:00.000Z
Link: CVE-2021-1624
Updated: 2024-08-03T16:18:10.396Z
Status : Modified
Published: 2021-09-23T03:15:13.610
Modified: 2024-11-21T05:44:46.050
Link: CVE-2021-1624
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD