CVE-2021-1624
Summary
| CVE | CVE-2021-1624 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-09-23 03:15:00 UTC |
| Updated | 2023-11-07 03:28:00 UTC |
| Description | A vulnerability in the Rate Limiting Network Address Translation (NAT) feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause high CPU utilization in the Cisco QuantumFlow Processor of an affected device, resulting in a denial of service (DoS) condition. This vulnerability is due to mishandling of the rate limiting feature within the QuantumFlow Processor. An attacker could exploit this vulnerability by sending large amounts of traffic that would be subject to NAT and rate limiting through an affected device. A successful exploit could allow the attacker to cause the QuantumFlow Processor utilization to reach 100 percent on the affected device, resulting in a DoS condition. |
Risk And Classification
Problem Types: NVD-CWE-Other
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Cisco | Asr 1000 | - | All | All | All |
| Hardware | Cisco | Asr 1000-esp100 | - | All | All | All |
| Hardware | Cisco | Asr 1000-x | - | All | All | All |
| Hardware | Cisco | Asr 1001 | - | All | All | All |
| Hardware | Cisco | Asr 1001-hx | - | All | All | All |
| Hardware | Cisco | Asr 1001-hx R | - | All | All | All |
| Hardware | Cisco | Asr 1001-x | - | All | All | All |
| Hardware | Cisco | Asr 1001-x R | - | All | All | All |
| Hardware | Cisco | Asr 1002 | - | All | All | All |
| Hardware | Cisco | Asr 1002-hx | - | All | All | All |
| Hardware | Cisco | Asr 1002-hx R | - | All | All | All |
| Hardware | Cisco | Asr 1002-x | - | All | All | All |
| Hardware | Cisco | Asr 1002-x R | - | All | All | All |
| Hardware | Cisco | Asr 1004 | - | All | All | All |
| Hardware | Cisco | Asr 1006 | - | All | All | All |
| Hardware | Cisco | Asr 1006-x | - | All | All | All |
| Hardware | Cisco | Asr 1009-x | - | All | All | All |
| Hardware | Cisco | Asr 1013 | - | All | All | All |
| Hardware | Cisco | Asr 1023 | - | All | All | All |
| Operating System | Cisco | Ios Xe | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Cisco IOS XE Software Rate Limiting Network Address Translation Denial of Service Vulnerability | CISCO | tools.cisco.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 317046 Cisco Internetwork Operating System (IOS) XE Software Rate Limiting Network Address Translation Denial of Service (DoS) Vulnerability (cisco-sa-ratenat-pYVLA7wM)