A vulnerability in the Common Open Policy Service (COPS) of Cisco IOS XE Software for Cisco cBR-8 Converged Broadband Routers could allow an unauthenticated, remote attacker to cause resource exhaustion, resulting in a denial of service (DoS) condition. This vulnerability is due to a deadlock condition in the code when processing COPS packets under certain conditions. An attacker could exploit this vulnerability by sending COPS packets with high burst rates to an affected device. A successful exploit could allow the attacker to cause the CPU to consume excessive resources, which prevents other control plane processes from obtaining resources and results in a DoS.
2021-09-23T03:15:13.353
2024-11-21T05:44:45.800
Modified
CVSSv3.1: 8.6 (HIGH)
AV:N/AC:M/Au:N/C:N/I:N/A:P
8.6
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | cisco | ios_xe | < 16.12.1z1 | Yes |
Operating System | cisco | ios_xe | 17.3.1x | Yes |
Hardware | cisco | 7600_router | - | No |
Hardware | cisco | asr_901-12c-f-d | - | No |
Hardware | cisco | asr_901-12c-ft-d | - | No |
Hardware | cisco | asr_901-4c-f-d | - | No |
Hardware | cisco | asr_901-4c-ft-d | - | No |
Hardware | cisco | asr_901-6cz-f-a | - | No |
Hardware | cisco | asr_901-6cz-f-d | - | No |
Hardware | cisco | asr_901-6cz-fs-a | - | No |
Hardware | cisco | asr_901-6cz-fs-d | - | No |
Hardware | cisco | asr_901-6cz-ft-a | - | No |
Hardware | cisco | asr_901-6cz-ft-d | - | No |
Hardware | cisco | cbr-8 | - | No |