Description
A vulnerability in the Layer 2 punt code of Cisco IOS XR Software running on Cisco ASR 9000 Series Aggregation Services Routers could allow an unauthenticated, adjacent attacker to cause the affected line card to reboot. This vulnerability is due to incorrect handling of specific Ethernet frames that cause a spin loop that can make the network processors unresponsive. An attacker could exploit this vulnerability by sending specific types of Ethernet frames on the segment where the affected line cards are attached. A successful exploit could allow the attacker to cause the affected line card to reboot.
Published: 2021-09-09
Score: 7.4 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2021-21363 A vulnerability in the Layer 2 punt code of Cisco IOS XR Software running on Cisco ASR 9000 Series Aggregation Services Routers could allow an unauthenticated, adjacent attacker to cause the affected line card to reboot. This vulnerability is due to incorrect handling of specific Ethernet frames that cause a spin loop that can make the network processors unresponsive. An attacker could exploit this vulnerability by sending specific types of Ethernet frames on the segment where the affected line cards are attached. A successful exploit could allow the attacker to cause the affected line card to reboot.
History

Thu, 07 Nov 2024 22:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Subscriptions

Cisco Asr 9000 Asr 9000v-v2 Asr 9001 Asr 9006 Asr 9010 Asr 9901 Asr 9902 Asr 9903 Asr 9904 Asr 9906 Asr 9910 Asr 9912 Asr 9922 Ios Xr
cve-icon MITRE

Status: PUBLISHED

Assigner: cisco

Published:

Updated: 2024-11-07T22:01:10.190Z

Reserved: 2021-06-15T00:00:00.000Z

Link: CVE-2021-34713

cve-icon Vulnrichment

Updated: 2024-08-04T00:19:48.108Z

cve-icon NVD

Status : Modified

Published: 2021-09-09T05:15:10.810

Modified: 2024-11-21T06:11:01.577

Link: CVE-2021-34713

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses