QID 316912
Date Published: 2021-04-05
QID 316912: Cisco IOS and IOS XE Software ARP Resource Management Exhaustion Denial of Service Vulnerability(cisco-sa-arp-mtfhBfjE)
A vulnerability in Address Resolution Protocol (ARP) management of Cisco IOS Software and Cisco IOS XE Software
could allow an unauthenticated, remote attacker to prevent an affected device
from resolving ARP entries for legitimate hosts on the connected subnets.
Affected Products
Cisco devices if they were running a vulnerable release of Cisco IOS or IOS XE Software.
QID Detection Logic (Authenticated):
The check matches Cisco IOS XE version retrieved via Unix Auth using "show version" command.
QID Detection Logic (Unauthenticated):
The check matches Cisco IOS XE version retrieved via SNMP or TCP/IP Fingerprint or NTP or Telnet.
A successful exploit could allow the attacker to cause ARP requests on the device to be unsuccessful
for legitimate hosts, resulting in a denial of service (DoS) condition.
Customers are advised to refer to cisco-sa-arp-mtfhBfjE for more information.
- cisco-sa-arp-mtfhBfjE -
tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-arp-mtfhBfjE
CVEs related to QID 316912
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| cisco-sa-arp-mtfhBfjE |
|