CVE-2021-1622

A vulnerability in the Common Open Policy Service (COPS) of Cisco IOS XE Software for Cisco cBR-8 Converged Broadband Routers could allow an unauthenticated, remote attacker to cause resource exhaustion, resulting in a denial of service (DoS) condition. This vulnerability is due to a deadlock condition in the code when processing COPS packets under certain conditions. An attacker could exploit this vulnerability by sending COPS packets with high burst rates to an affected device. A successful exploit could allow the attacker to cause the CPU to consume excessive resources, which prevents other control plane processes from obtaining resources and results in a DoS.
Configurations

Configuration 1 (hide)

AND
OR cpe:2.3:o:cisco:ios_xe:*:*:*:*:*:*:*:*
cpe:2.3:o:cisco:ios_xe:17.3.1x:*:*:*:*:*:*:*
OR cpe:2.3:h:cisco:7600_router:-:*:*:*:*:*:*:*
cpe:2.3:h:cisco:asr_901-12c-f-d:-:*:*:*:*:*:*:*
cpe:2.3:h:cisco:asr_901-12c-ft-d:-:*:*:*:*:*:*:*
cpe:2.3:h:cisco:asr_901-4c-f-d:-:*:*:*:*:*:*:*
cpe:2.3:h:cisco:asr_901-4c-ft-d:-:*:*:*:*:*:*:*
cpe:2.3:h:cisco:asr_901-6cz-f-a:-:*:*:*:*:*:*:*
cpe:2.3:h:cisco:asr_901-6cz-f-d:-:*:*:*:*:*:*:*
cpe:2.3:h:cisco:asr_901-6cz-fs-a:-:*:*:*:*:*:*:*
cpe:2.3:h:cisco:asr_901-6cz-fs-d:-:*:*:*:*:*:*:*
cpe:2.3:h:cisco:asr_901-6cz-ft-a:-:*:*:*:*:*:*:*
cpe:2.3:h:cisco:asr_901-6cz-ft-d:-:*:*:*:*:*:*:*
cpe:2.3:h:cisco:cbr-8:-:*:*:*:*:*:*:*

History

23 Nov 2021, 13:10

Type Values Removed Values Added
CPE cpe:2.3:a:cisco:ios_xe:*:*:*:*:*:*:*:*
cpe:2.3:a:cisco:ios_xe:17.3.1x:*:*:*:*:*:*:*
cpe:2.3:o:cisco:ios_xe:17.3.1x:*:*:*:*:*:*:*
cpe:2.3:o:cisco:ios_xe:*:*:*:*:*:*:*:*

30 Sep 2021, 15:49

Type Values Removed Values Added
CPE cpe:2.3:h:cisco:asr_901-6cz-f-a:-:*:*:*:*:*:*:*
cpe:2.3:h:cisco:asr_901-6cz-ft-d:-:*:*:*:*:*:*:*
cpe:2.3:a:cisco:ios_xe:17.3.1x:*:*:*:*:*:*:*
cpe:2.3:h:cisco:asr_901-12c-f-d:-:*:*:*:*:*:*:*
cpe:2.3:h:cisco:asr_901-12c-ft-d:-:*:*:*:*:*:*:*
cpe:2.3:h:cisco:asr_901-6cz-fs-a:-:*:*:*:*:*:*:*
cpe:2.3:h:cisco:asr_901-4c-ft-d:-:*:*:*:*:*:*:*
cpe:2.3:h:cisco:asr_901-6cz-f-d:-:*:*:*:*:*:*:*
cpe:2.3:h:cisco:asr_901-6cz-fs-d:-:*:*:*:*:*:*:*
cpe:2.3:h:cisco:asr_901-4c-f-d:-:*:*:*:*:*:*:*
cpe:2.3:h:cisco:asr_901-6cz-ft-a:-:*:*:*:*:*:*:*
cpe:2.3:h:cisco:cbr-8:-:*:*:*:*:*:*:*
cpe:2.3:h:cisco:7600_router:-:*:*:*:*:*:*:*
cpe:2.3:a:cisco:ios_xe:*:*:*:*:*:*:*:*
CWE CWE-667
References (CISCO) https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cbr8-cops-Vc2ZsJSx - (CISCO) https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cbr8-cops-Vc2ZsJSx - Patch, Vendor Advisory
CVSS v2 : unknown
v3 : unknown
v2 : 4.3
v3 : 8.6

23 Sep 2021, 03:15

Type Values Removed Values Added
New CVE

Information

Published : 2021-09-23 03:15

Updated : 2024-02-04 22:08


NVD link : CVE-2021-1622

Mitre link : CVE-2021-1622

CVE.ORG link : CVE-2021-1622


JSON object : View

Products Affected

cisco

  • 7600_router
  • asr_901-6cz-ft-a
  • asr_901-6cz-fs-a
  • asr_901-4c-ft-d
  • asr_901-12c-f-d
  • ios_xe
  • asr_901-6cz-f-d
  • asr_901-4c-f-d
  • asr_901-6cz-ft-d
  • cbr-8
  • asr_901-12c-ft-d
  • asr_901-6cz-fs-d
  • asr_901-6cz-f-a
CWE
CWE-667

Improper Locking

CWE-833

Deadlock