CVE-2021-1285
published 2024-11-18CVE-2021-1285: Multiple Cisco products are affected by a vulnerability in the Ethernet Frame Decoder of the Snort detection engine that could allow an unauthenticated…
PriorityP340high7.4CVSS 3.0
AVAACLPRNUINSCCNINAH
EPSS
2.76%
84.6th percentile
Multiple Cisco products are affected by a vulnerability in the Ethernet Frame Decoder of the Snort detection engine that could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition.
The vulnerability is due to improper handling of error conditions when processing Ethernet frames. An attacker could exploit this vulnerability by sending malicious Ethernet frames through an affected device. A successful exploit could allow the attacker to exhaust disk space on the affected device, which could result in administrators being unable to log in to the device or the device being unable to boot up correctly.Note: Manual intervention is required to recover from this situation. Customers are advised to contact the Cisco Technical Assistance Center (TAC) to help recover a device in this condition.Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.
Affected
27 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | cisco_utd_snort_ips_engine_software | — | — |
| cisco | cisco_utd_snort_ips_engine_software | — | — |
| cisco | cisco_utd_snort_ips_engine_software | — | — |
| cisco | cisco_utd_snort_ips_engine_software | — | — |
| cisco | cisco_utd_snort_ips_engine_software | — | — |
| cisco | cisco_utd_snort_ips_engine_software | — | — |
| cisco | cisco_utd_snort_ips_engine_software | — | — |
| cisco | cisco_utd_snort_ips_engine_software | — | — |
| cisco | cisco_utd_snort_ips_engine_software | — | — |
| cisco | cisco_utd_snort_ips_engine_software | — | — |
| cisco | cisco_utd_snort_ips_engine_software | — | — |
| cisco | cisco_utd_snort_ips_engine_software | — | — |
| cisco | cisco_utd_snort_ips_engine_software | — | — |
| cisco | cisco_utd_snort_ips_engine_software | — | — |
| cisco | cisco_utd_snort_ips_engine_software | — | — |
| cisco | cisco_utd_snort_ips_engine_software | — | — |
| cisco | cisco_utd_snort_ips_engine_software | — | — |
| cisco | cisco_utd_snort_ips_engine_software | — | — |
| cisco | cisco_utd_snort_ips_engine_software | — | — |
| cisco | cisco_utd_snort_ips_engine_software | — | — |
| cisco | cisco_utd_snort_ips_engine_software | — | — |
| cisco | cisco_utd_snort_ips_engine_software | — | — |
| cisco | cisco_utd_snort_ips_engine_software | — | — |
| cisco | cisco_utd_snort_ips_engine_software | — | — |
| cisco | cisco_utd_snort_ips_engine_software | — | — |
CVSS provenance
nvdv3.07.4HIGHCVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
vendor_oracle9.8CRITICAL
vendor_cisco7.4HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Oracle
Oracle Oracle Hospitality Applications Risk Matrix: Logging (Apache log4net) — CVE-2018-1285
vendor_oracle·2021-04-15·CVSS 9.8
CVE-2018-1285 [CRITICAL] Oracle Oracle Hospitality Applications Risk Matrix: Logging (Apache log4net) — CVE-2018-1285
Oracle Oracle Hospitality Applications Risk Matrix: Logging (Apache log4net) vulnerability
CVE: CVE-2018-1285
CVSS: 9.8
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuapr2021 (APR 2021)
Cisco
Multiple Cisco Products Snort Ethernet Frame Decoder Denial of Service Vulnerability
vendor_cisco·2021-03-03·CVSS 7.4
CVE-2021-1285 [HIGH] CWE-770 Multiple Cisco Products Snort Ethernet Frame Decoder Denial of Service Vulnerability
Multiple Cisco Products Snort Ethernet Frame Decoder Denial of Service Vulnerability
Multiple Cisco products are affected by a vulnerability in the Ethernet Frame Decoder of the Snort detection engine that could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition.
The vulnerability is due to improper handling of error conditions when processing Ethernet frames. An attacker could exploit this vulnerability by sending malicious Ethernet frames through an affected device. A successful exploit could allow the attacker to exhaust disk space on the affected device, which could result in administrators being unable to log in to the device or the device being unable to boot up correctly.
Note: Manual intervention is required to recover from this situation. Cu
Oracle
Oracle Oracle Food and Beverage Applications Risk Matrix: Simphony Server (Apache log4net) — CVE-2018-1285
vendor_oracle·2021-01-15·CVSS 9.8
CVE-2018-1285 [CRITICAL] Oracle Oracle Food and Beverage Applications Risk Matrix: Simphony Server (Apache log4net) — CVE-2018-1285
Oracle Oracle Food and Beverage Applications Risk Matrix: Simphony Server (Apache log4net) vulnerability
CVE: CVE-2018-1285
CVSS: 9.8
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujan2021 (JAN 2021)
Cisco
Multiple Cisco Products Snort Ethernet Frame Decoder Denial of Service Vulnerability
vendor_cisco·CVSS 3.0
CVE-2021-1285 Multiple Cisco Products Snort Ethernet Frame Decoder Denial of Service Vulnerability
CVE-2021-1285: Multiple Cisco Products Snort Ethernet Frame Decoder Denial of Service Vulnerability
Multiple Cisco products are affected by a vulnerability in the Ethernet Frame Decoder of the Snort detection engine that could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition. The vulnerability is due to improper handling of error conditions when processing Ethernet frames. An attacker could exploit this vulnerability by sending malicious Ethernet frames through an affected device. A successful exploit could allow the attacker to exhaust disk space on the affected device, which could result in administrators being unable to log in to the device or the device being unable to boot up correctly. Note: Manual intervention is required to recover from this
GHSA
GHSA-278j-256r-v8r4: Multiple Cisco products are affected by a vulnerability in the Ethernet Frame Decoder of the Snort detection engine that could allow an unauthenticate
ghsa_unreviewed·2024-11-18
CVE-2021-1285 [HIGH] CWE-770 GHSA-278j-256r-v8r4: Multiple Cisco products are affected by a vulnerability in the Ethernet Frame Decoder of the Snort detection engine that could allow an unauthenticate
Multiple Cisco products are affected by a vulnerability in the Ethernet Frame Decoder of the Snort detection engine that could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition.
The vulnerability is due to improper handling of error conditions when processing Ethernet frames. An attacker could exploit this vulnerability by sending malicious Ethernet frames through an affected device. A successful exploit could allow the attacker to exhaust disk space on the affected device, which could result in administrators being unable to log in to the device or the device being unable to boot up correctly.Note: Manual intervention is required to recover from this situation. Customers are advised to contact the Cisco Technical Assistance Center (TAC) to help recov
No detection rules found.
No public exploits indexed.
Talos
Vulnerability Spotlight: Multiple vulnerabilities in D-LINK DIR-3040
blogs_talos·2021-07-15·CVSS 4.3
CVE-2021-21816 [MEDIUM] Vulnerability Spotlight: Multiple vulnerabilities in D-LINK DIR-3040
Dave McDaniel discovered these vulnerabilities. Blog by Jon Munshaw.
Cisco Talos recently discovered multiple vulnerabilities in the D-LINK DIR-3040 wireless router.
The DIR-3040 is an AC3000-based wireless internet router. These vulnerabilities could allow an attacker to carry out a variety of malicious actions, including exposing sensitive information, causing a denial of service and gaining the ability to execute arbitrary code. TALOS-2021-1281 (CVE-2021-21816) and TALOS-2021-1282 (CVE-2021-21817) are information disclosure vulnerabilities in the router that could be triggered by a specially crafted network request. An attacker could exploit these vulnerabilities to view the device’s system log.
TALOS-2021-1283 (CVE-2021-21818) and TALOS-2021-1285 (CVE-2021-21820) are both hardcoded
Checkpoint
8th March – Threat Intelligence Report
blogs_checkpoint·2021-03-08
CVE-2021-1285 8th March – Threat Intelligence Report
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
## 8th March – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 8th March, please download our Threat Intelligence Bulletin .
Top Attacks and Breaches
SITA, a communications and IT vendor for 90 percent of the world’s airlines, has been breached in a massive supply-chain attack, compromising frequent-flyer data across many carriers such as United, Singapore Airlines, Lufthansa, and more.
Spirit Airlines has suffered a data breach by “Nefilim” ransomware. A first batch of cus
2024-11-18
Published