QID 316994
Date Published: 2021-07-12
QID 316994: Cisco Internetwork Operating System (IOS-XE) Vulnerability in Open Secure Sockets Layer (OpenSSL) Affecting Cisco Products (cisco-sa-openssl-2021-GHY28dJd)
Cisco IOS XE is impacted by CVE-2021-3449, OpenSSL NULL Pointer Dereference Denial of Service Vulnerability
that could allow an attacker to cause a denial of service (DoS) condition on a targeted system.
Affected Products
Cisco IOS XE below versions if running on below platform :
Cisco Cloud Services Router 1000V Series
Cisco 2600 Series Multiservice Platforms
Affected Releases:
From IOS XE 17.3.1 Prior to IOS XE 17.3(3.9)
Note: Potential detection as cannot confirm the platform.
QID Detection Logic (Authenticated):
The check matches Cisco IOS XE version retrieved via Unix Auth using "show version" command.
QID Detection Logic (Unauthenticated):
The check matches Cisco IOS XE version retrieved via SNMP or TCP/IP Fingerprint or NTP or Telnet.
Successful exploitation could allow a remote unauthenticated attacker to crash a TLS server resulting in a Denial of Service (DoS) condition.
Customers are advised to refer to cisco-sa-openssl-2021-GHY28dJd for more information.
- cisco-sa-openssl-2021-GHY28dJd -
tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-openssl-2021-GHY28dJd
CVEs related to QID 316994
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| cisco-sa-openssl-2021-GHY28dJd |
|